The vulnerability is in do_pnm2png() in contrib/pngminus/pnm2png.c, which
isn't built by any package exported by debian. This file is not declared
in any header, nor referenced in any build-system file, nor included in
Debian's packaging rules or .install files.