libpng: does not check length of chunks against user limit
Published Jul 10, 2019
9.8
CRITICALCVSS 3.1
EPSS 4.11%
Description
libpng before 1.6.32 does not properly check the length of chunks against the user limit.
Affected products
No data.
Configuration 2
- n/a
No data.
Red Hat Enterprise Linux 7
libpng-2:1.5.13-8.el7
Fixed · RHSA-2020:3901
Red Hat Enterprise Linux 5
libpng
Out of support scope
Red Hat Enterprise Linux 6
libpng
Out of support scope
Red Hat Enterprise Linux 8
libpng
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 | libpng-2:1.5.13-8.el7 | Fixed | RHSA-2020:3901 |
| Red Hat Enterprise Linux 5 | libpng | Out of support scope | n/a |
| Red Hat Enterprise Linux 6 | libpng | Out of support scope | n/a |
| Red Hat Enterprise Linux 8 | libpng | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
AV:N/AC:L/Au:N/C:P/I:P/A:P
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
YesTechnical Impact
TotalDecision
n/aAssessed Jun 9, 2025 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v5
Percentile over time
- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v5
Table of values (16 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 4.11% (0.04113) | 90.46th | v5 (v2026.06.15) |
| Jun 15, 2026 | 4.08% (0.04079) | 89.36th | v5 (v2026.06.15) |
| Nov 30, 2024 | 1.53% (0.01531) | 87.60th | v3 (v2023.03.01) |
| Jul 3, 2024 | 3.19% (0.03194) | 91.25th | v3 (v2023.03.01) |
| Dec 6, 2023 | 2.79% (0.02794) | 89.51th | v3 (v2023.03.01) |
| Nov 8, 2023 | 2.93% (0.02931) | 89.73th | v3 (v2023.03.01) |
| Aug 3, 2023 | 2.33% (0.02332) | 88.30th | v3 (v2023.03.01) |
| Mar 7, 2023 | 3.27% (0.03269) | 89.74th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.02% (0.01018) | 40.69th | v2 (v2022.01.01) |
| Sep 10, 2022 | 1.02% (0.01018) | 38.88th | v2 (v2022.01.01) |
| Apr 1, 2022 | 1.02% (0.01018) | 36.86th | v2 (v2022.01.01) |
| Feb 4, 2022 | 1.02% (0.01018) | 19.50th | v2 (v2022.01.01) |
| Feb 3, 2022 | 1.04% (0.01040) | 28.32th | v1 |
| Jan 6, 2022 | 1.04% (0.01040) | 27.69th | v1 |
| Sep 1, 2021 | 1.04% (0.01040) | 64.49th | v1 |
| Apr 14, 2021 | 1.04% (0.01040) | 0.00th | v1 |
References (11)
- http://www.securityfocus.com/bid/109269 vdb-entryBroken LinkThird Party AdvisoryVDB Entry
- https://access.redhat.com/security/cve/CVE-2017-12652 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1733956 Issue Tracking
- https://github.com/glennrp/libpng/blob/df7e9dae0c4aac63d55361e35709c864fa1b8363/ANNOUNCE Release NotesThird Party Advisory
- https://github.com/pnggroup/libpng/commit/347538efbdc21b8df684ebd92d37400b3ce85d55
- https://nvd.nist.gov/vuln/detail/CVE-2017-12652
- https://security.netapp.com/advisory/ntap-20220506-0003/ Third Party Advisory
- https://support.f5.com/csp/article/K88124225 Third Party Advisory
- https://support.f5.com/csp/article/K88124225?utm_source=f5support&%3Butm_medium=RSS
- https://support.f5.com/csp/article/K88124225?utm_source=f5support&utm_medium=RSS
- https://www.cve.org/CVERecord?id=CVE-2017-12652
| Link | Providers | Tags |
|---|---|---|
| http://www.securityfocus.com/bid/109269 | vdb-entryBroken LinkThird Party AdvisoryVDB Entry | |
| https://access.redhat.com/security/cve/CVE-2017-12652 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1733956 | Issue Tracking | |
| https://github.com/glennrp/libpng/blob/df7e9dae0c4aac63d55361e35709c864fa1b8363/ANNOUNCE | Release NotesThird Party Advisory | |
| https://github.com/pnggroup/libpng/commit/347538efbdc21b8df684ebd92d37400b3ce85d55 | ||
| https://nvd.nist.gov/vuln/detail/CVE-2017-12652 | ||
| https://security.netapp.com/advisory/ntap-20220506-0003/ | Third Party Advisory | |
| https://support.f5.com/csp/article/K88124225 | Third Party Advisory | |
| https://support.f5.com/csp/article/K88124225?utm_source=f5support&%3Butm_medium=RSS | ||
| https://support.f5.com/csp/article/K88124225?utm_source=f5support&utm_medium=RSS | ||
| https://www.cve.org/CVERecord?id=CVE-2017-12652 |
Change history (0)
No recorded changes yet.