Description
png_create_info_struct in png.c in libpng 1.6.36 has a memory leak, as demonstrated by pngcp. NOTE: a third party has stated "I don't think it is libpng's job to free this buffer.
Mitigation
Minimal update. May introduce new vulnerabilities or breaking changes.
|
 debian 11 | | =1.6.37-3 || =1.6.37-3+deb11u1 || =1.6.37-3+deb11u2 || =1.6.37-3+deb11u3 || =1.6.37-4 || =1.6.37-5 || =1.6.38-1 || =1.6.38-2 || =1.6.39-1 || =1.6.39-2 || =1.6.40-1 || =1.6.40-2 || =1.6.40-3 || =1.6.41-1 || =1.6.42-1 || =1.6.42-1.1~exp1 || =1.6.43-1 || =1.6.43-1exp1 || =1.6.43-2 || =1.6.43-3 || =1.6.43-4 || =1.6.43-5 || =1.6.44-1 || =1.6.44-2 || =1.6.44-3 || =1.6.45-1 || =1.6.46-1 || =1.6.46-2 || =1.6.46-3 || =1.6.46-4 || =1.6.47-1 || =1.6.47-1.1 || =1.6.48-1 || =1.6.49-1~exp1 || =1.6.50-1 || =1.6.50-1~exp1 || =1.6.51-1 || =1.6.52-1 || =1.6.53-1 || =1.6.54-1 || =1.6.55-1 || =1.6.56-1 || =1.6.57-1 || =1.6.58-1 | - |
 debian 14 | | | 1.6.39-1 |
 debian 13 | | | 1.6.39-1 |
 debian 12 | | | 1.6.39-1 |