This update for netpbm fixes the following issues:
Security issues fixed:
CVE-2018-8975: The pm_mallocarray2 function allowed remote attackers to cause
a denial of service (heap-based buffer over-read) via a crafted image file (bsc#1086777).
CVE-2017-2579: Fixed out-of-bounds read in expandCodeOntoStack() (bsc#1024288).
CVE-2017-2580: Fixed out-of-bounds write of heap data in addPixelToRaster() function (bsc#1024291).
create netpbm-vulnerable subpackage and move pstopnm there (bsc#1136936)