VDB

DEBIAN-CVE-2019-6129

DEBIAN-CVE-2019-6129 PUBLISHED CVSS 6.5 MEDIUM

png_create_info_struct in png.c in libpng 1.6.36 has a memory leak, as demonstrated by pngcp. NOTE: a third party has stated "I don't think it is libpng's job to free this buffer.

Risk Scores

CVSS 3.0
6.5
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Affected Products

VendorProductVersions
Debian:12libpng1.60, 0, 0
Debian:11libpng1.61.6.44-1, 1.6.43-1, *
Debian:14libpng1.60, 0, 0
Debian:13libpng1.60, 0, 0

Timeline

  • Jan 11, 2019 CVE Published
  • Apr 28, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›