Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-66293

Опубликовано: 03 дек. 2025
Источник: redhat
CVSS3: 7.1
EPSS Низкий

Описание

LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. Prior to 1.6.52, an out-of-bounds read vulnerability in libpng's simplified API allows reading up to 1012 bytes beyond the png_sRGB_base[512] array when processing valid palette PNG images with partial transparency and gamma correction. The PNG files that trigger this vulnerability are valid per the PNG specification; the bug is in libpng's internal state management. Upgrade to libpng 1.6.52 or later.

An out of bounds read vulnerability has been discovered in libpng. This vulnerability is in libpng's simplified API allows reading up to 1012 bytes beyond the png_sRGB_base[512] array when processing valid palette PNG images with partial transparency and gamma correction. The PNG files that trigger this vulnerability are valid per the PNG specification; the bug is in libpng's internal state management.

Отчет

The Red Hat Product Security team has rated this vulnerability as Important as it affects libpng, a widely used library for PNG image processing. The flaw is due to an out-of-bounds read in libpng’s simplified API when handling specially crafted PNG images containing partial transparency and gamma correction data. Successful exploitation could result in information disclosure or cause application crashes in applications processing untrusted PNG content. For java-17-openjdk-headless and java-21-openjdk-headless, while the affected code is present in the bundled sources, it is not exercised by these headless packages.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat build of OpenJDK 11 ELSjava-11-openjdkAffected
Red Hat build of OpenJDK 11 ELSjava-11-openjdk-portableAffected
Red Hat build of OpenJDK 11 ELSjava-21-openjdk-portableNot affected
Red Hat build of OpenJDK 17java-17-openjdk-portableAffected
Red Hat build of OpenJDK 17java-21-openjdk-portableNot affected
Red Hat build of OpenJDK 1.8java-1.8.0-openjdk-portableAffected
Red Hat build of OpenJDK 21java-21-openjdk-portableAffected
Red Hat build of OpenJDK 21java-21-openjdk-portable-rhel7Not affected
Red Hat build of OpenJDK 25java-21-openjdk-vanillaNot affected
Red Hat build of OpenJDK 25java-25-openjdk-portableAffected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=2418711libpng: LIBPNG out-of-bounds read in png_image_read_composite

EPSS

Процентиль: 24%
0.00082
Низкий

7.1 High

CVSS3

Связанные уязвимости

CVSS3: 7.1
ubuntu
4 месяца назад

LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. Prior to 1.6.52, an out-of-bounds read vulnerability in libpng's simplified API allows reading up to 1012 bytes beyond the png_sRGB_base[512] array when processing valid palette PNG images with partial transparency and gamma correction. The PNG files that trigger this vulnerability are valid per the PNG specification; the bug is in libpng's internal state management. Upgrade to libpng 1.6.52 or later.

CVSS3: 7.1
nvd
4 месяца назад

LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. Prior to 1.6.52, an out-of-bounds read vulnerability in libpng's simplified API allows reading up to 1012 bytes beyond the png_sRGB_base[512] array when processing valid palette PNG images with partial transparency and gamma correction. The PNG files that trigger this vulnerability are valid per the PNG specification; the bug is in libpng's internal state management. Upgrade to libpng 1.6.52 or later.

CVSS3: 7.1
msrc
4 месяца назад

LIBPNG has an out-of-bounds read in png_image_read_composite

CVSS3: 7.1
debian
4 месяца назад

LIBPNG is a reference library for use in applications that read, creat ...

suse-cvrf
3 месяца назад

Security update for libpng16

EPSS

Процентиль: 24%
0.00082
Низкий

7.1 High

CVSS3