First published: Fri Jan 11 2019(Updated: )
** DISPUTED ** png_create_info_struct in png.c in libpng 1.6.36 has a memory leak, as demonstrated by pngcp. NOTE: a third party has stated "I don't think it is libpng's job to free this buffer."
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Libpng Libpng | =1.6.36 | |
=1.6.36 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
** DISPUTED ** png_create_info_struct in png.c in libpng 1.6.36 has a memory leak, as demonstrated by pngcp. NOTE: a third party has stated "I don't think it is libpng's job to free this buffer."
Libpng version 1.6.36 is affected by CVE-2019-6129.
The severity of CVE-2019-6129 is medium (6.5).
There is currently no known fix for CVE-2019-6129. It is recommended to follow the advice of the software vendor or project team.
You can find more information about CVE-2019-6129 on the GitHub issue page (https://github.com/glennrp/libpng/issues/269) and the Oracle security advisory (https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html).