CVE-2019-6129
MEDIUMlibpng 1.6.36 - Memory Leak in png_create_info_struct
Title source: llmDescription
png_create_info_struct in png.c in libpng 1.6.36 has a memory leak, as demonstrated by pngcp. NOTE: a third party has stated "I don't think it is libpng's job to free this buffer.
References (2)
Core 2
Core References
Exploit, Third Party Advisory x_refsource_misc
https://github.com/glennrp/libpng/issues/269
Scores
CVSS v3
6.5
EPSS
0.0139
EPSS Percentile
68.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-401
Status
published
Products (1)
libpng/libpng
1.6.36
Published
Jan 11, 2019
Tracked Since
Feb 18, 2026