Out-of-Bounds Read Vulnerability in libpng Library Affecting PNG Image Processing
CVE-2025-66293
7.1HIGH
What is CVE-2025-66293?
The libpng library, which is widely used for handling PNG (Portable Network Graphics) files, contains an out-of-bounds read vulnerability in its simplified API prior to version 1.6.52. This flaw can lead to reading data beyond the allocated memory, particularly when processing valid palette PNG images that exhibit partial transparency and gamma correction. The issue arises from libpng's internal state management during image processing. Users are encouraged to upgrade to libpng version 1.6.52 or later to address this security concern effectively.
Affected Version(s)
libpng < 1.6.52
