{"id":"ECHO-9e0d-9055-5bf6","summary":"The vulnerability is in do_pnm2png() in contrib/pngminus/pnm2png.c, which\nisn't built by any package exported by debian. This file is not declared\nin any header, nor referenced in any build-system file, nor included in\nDebian's packaging rules or .install files.\n","modified":"2026-09-15T00:47:47.421995900Z","published":"2026-03-09T02:30:06.586565Z","withdrawn":"2026-04-05T18:15:03.523Z","upstream":["CVE-2026-3713"],"references":[{"type":"WEB","url":"https://advisory.echohq.com/cve/CVE-2026-3713"}],"affected":[{"package":{"name":"libpng1.6","ecosystem":"Echo","purl":"pkg:deb/echo/libpng1.6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.6.56-1+e1"}]}],"database_specific":{"source":"https://advisory.echohq.com/osv/ECHO-9e0d-9055-5bf6.json"}}],"schema_version":"1.9.0"}