CVE-2019-6129 PUBLISHED

png_create_info_struct in png.c in libpng 1.6.36 has a memory leak, as demonstrated by pngcp. NOTE: a third party has stated "I don't think it is libpng's job to free this buffer.

EPSS 0.28% · 51.6th percentile

Risk Scores

EPSS Score
0.28%
51.6th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:16.04:LTSlibpng1.61.6.20-2ubuntu0.1~esm2, 1.6.20-2ubuntu0.1~esm3, 0
Ubuntu:Pro:16.04:LTSlibpng1.2.54-1ubuntu1, 1.2.54-1, 1.2.54-1ubuntu1.1
Ubuntu:14.04:LTSlibpng0, 1.2.49-4ubuntu1, 1.2.49-5ubuntu1
Ubuntu:Pro:18.04:LTSlibpng1.60, 1.6.34-1, 1.6.34-1ubuntu0.18.04.1

Timeline

References

Open in Interactive Console →