Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2017-12652

33
FAUCET Score

CVE-2017-12652 is a critical vulnerability in libpng versions prior to 1.6.32, affecting products like NetApp Active IQ Unified Manager, where it fails to properly validate the length of chunks against user-defined limits. This vulnerability carries a CVSS score of 9.8 (CRITICAL), indicating it can be exploited remotely without authentication or user interaction, leading to complete compromise of confidentiality, integrity, and availability. Despite its high severity and significant community discussion (10 mentions), there is currently no evidence of active exploitation, nor are public exploit tools like Metasploit, Nuclei, or ExploitDB available.

Impacted Technologies

VendorProductVersion(s)CPE
< 1.6.32CPE matchmatch criteria
cpe:2.3:a:libpng:libpng:*:*:*:*:*:*:*:*
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vsphere:*:*

CVSS Data

CVSS version used by this source: 3.1

9.8CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
4.11%
Probability of exploitation in next 30 days
EPSS Percentile
89.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-24
Model: v2026.06.15
This CVE's current EPSS score of 0.0411 is in the 83rd percentile among its peer group of 36,829 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (5)

microsoftpatch availablevia msrc
Product: 16826-17084Fixed in: 1.3.8-1
microsoftpatch availablevia msrc
Product: 16826-16817Fixed in: 1.3.8-1
microsoftpatch availablevia msrc
Product: azl3 fltk 1.3.8-1 on Azure Linux 3.0Fixed in: 1.3.8-1
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: libpng-2:1.5.13-8.el7
View patch
gcpvendor investigatingvia llm_extracted
View patch

Vendor Advisories (3)

gcpllm-gcp-011b49b2d0496758CRITICAL

HP Universal Print Driver Series (PCL 6 and PostScript) - Potential Security Vulnerabilities

Jan 29, 2025
redhatCVE-2017-12652Low

libpng: does not check length of chunks against user limit

Jul 10, 2019
microsoft2019-Jul/CVE-2017-12652Critical

libpng before 1.6.32 does not properly check the length of chunks against the user limit.

Jul 9, 2019

References

support.f5.com / csp/article/K88124225
github.com / glennrp/libpng/blob/df7e9dae0c4aac63d55361e35709c864fa1b8363/ANNOUNCE
Release NotesThird Party Advisory
github.com / pnggroup/libpng/commit/347538efbdc21b8df684ebd92d37400b3ce85d55
security.netapp.com / advisory/ntap-20220506-0003
Third Party Advisory
support.f5.com / csp/article/K88124225
Third Party Advisory
support.f5.com / csp/article/K88124225
securityfocus.com / bid/109269
Broken LinkThird Party AdvisoryVDB Entry