WRITEUP

WRITEUP
Exploit for CVE-2026-3713 - libpng <=1.6.55 - Buffer Overflow
AI Analysis

The repository contains a detailed technical analysis of CVE-2026-3713, focusing on an out-of-bounds read vulnerability in libheif's `vvdec_push_data2()` function due to missing length validation. It includes vulnerable code snippets, a comparison with a properly guarded function, and an ASAN trace demonstrating the heap-buffer-overflow.

Attack Type
DoS
Complexity
moderate
Reliability
reliable
MITRE ATT&CK
T1499 - Endpoint Denial of Service
Loading exploit code...
Download ZIP Password: eip
Source
Platform Writeup
Type poc
Files 4
Authors
biniamf
Vulnerability
CVE-2026-3713
libpng <=1.6.55 - Buffer Overflow
MEDIUM
CVSS 5.3