Applications using libpng versions 1.6.0 through 1.6.58 are affected only if they call png_read_end before beginning to read image rows. The vulnerable path involves incomplete decompression of crafted zTXt, iTXt, or iCCP chunks.
An attacker needs a crafted PNG containing a zTXt, iTXt, or iCCP chunk that causes libpng to abandon decompression while zlib still expects input. Examples include an invalid zlib window size, decompressed data exceeding libpng limits, or an ICC profile that fails validation.
The provided CVSS vector rates the issue as network-accessible with no privileges or user interaction required, but with high attack complexity. Its stated impact is availability only, with high availability impact and no confidentiality or integrity impact.
Apply the referenced fix commit aa77ef38c17ab2fc1b41bec09fb973c6a386641d. Otherwise, avoid the affected usage pattern of calling png_read_end before starting to read image rows.