pngcreateinfo_struct in png.c in libpng 1.6.36 has a memory leak, as demonstrated by pngcp. NOTE: a third party has stated "I don't think it is libpng's job to free this buffer.
{ "binaries": [ { "binary_version": "1.2.50-1ubuntu2.14.04.3+esm1", "binary_name": "libpng12-0" }, { "binary_version": "1.2.50-1ubuntu2.14.04.3+esm1", "binary_name": "libpng3" } ] }
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2019/UBUNTU-CVE-2019-6129.json"
{ "binaries": [ { "binary_version": "1.2.54-1ubuntu1.1+esm2", "binary_name": "libpng12-0" }, { "binary_version": "1.2.54-1ubuntu1.1+esm2", "binary_name": "libpng3" } ] }
{ "binaries": [ { "binary_version": "1.6.20-2ubuntu0.1~esm3", "binary_name": "libpng16-16" }, { "binary_version": "1.6.20-2ubuntu0.1~esm3", "binary_name": "libpng16-devtools" }, { "binary_version": "1.6.20-2ubuntu0.1~esm3", "binary_name": "libpng16-tools" } ] }
{ "binaries": [ { "binary_version": "1.6.34-1ubuntu0.18.04.2+esm2", "binary_name": "libpng-tools" }, { "binary_version": "1.6.34-1ubuntu0.18.04.2+esm2", "binary_name": "libpng16-16" } ] }