CVE-2026-3713

EUVD-2026-10219
A flaw has been found in pnggroup libpng up to 1.6.55. Affected by this vulnerability is the function do_pnm2png of the file contrib/pngminus/pnm2png.c of the component pnm2png. This manipulation of the argument width/height causes heap-based buffer overflow. The attack is restricted to local execution. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.3 MEDIUM
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 2.53%
Debian logo
Debian Releases
Debian Product
Codename
libpng1.6
bookworm
unimportant
bookworm (security)
unimportant
forky
unimportant
sid
unimportant
trixie
unimportant
trixie (security)
unimportant
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
chromium-browser
jammy
not-affected
noble
not-affected
questing
not-affected
resolute
not-affected
firefox
jammy
not-affected
noble
not-affected
questing
not-affected
resolute
not-affected
libpng
jammy
dne
noble
dne
questing
dne
resolute
dne
trusty
needs-triage
xenial
not-affected
libpng1.6
bionic
not-affected
focal
not-affected
jammy
not-affected
noble
not-affected
questing
not-affected
resolute
not-affected
xenial
not-affected
thunderbird
jammy
not-affected
noble
not-affected
questing
not-affected
resolute
not-affected