CVE-2026-3713: pnggroup libpng pnm2png pnm2png.c do_pnm2png heap-based overflow
A flaw has been found in pnggroup libpng up to 1.6.55. Affected by this vulnerability is the function dopnm2png of the file contrib/pngminus/pnm2png.c of the component pnm2png. This manipulation of the argument width/height causes heap-based buffer overflow. The attack is restricted to local execution. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-3713?
CVE-2026-3713 has been classified as a high severity vulnerability due to its potential for a heap-based overflow.
How do I fix CVE-2026-3713?
To fix CVE-2026-3713, upgrade the libpng software to version 1.6.56 or later, which addresses the vulnerability.
Which versions of libpng are affected by CVE-2026-3713?
CVE-2026-3713 affects libpng versions up to and including 1.6.55.
What component is vulnerable in CVE-2026-3713?
The vulnerable component in CVE-2026-3713 is the pnm2png tool, specifically the do_pnm2png function in pnm2png.c.
Is there any exploit available for CVE-2026-3713?
There is a potential for exploitation of CVE-2026-3713 due to the heap-based overflow, making systems vulnerable to arbitrary code execution.