CVE-2019-19952Use After Free in Imagemagick

CWE-416Use After Free7 documents5 sources
Severity
9.8CRITICALNVD
EPSS
0.5%
top 36.05%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 24
Latest updateMay 24

Description

In ImageMagick 7.0.9-7 Q16, there is a use-after-free in the function MngInfoDiscardObject of coders/png.c, related to ReadOneMNGImage.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages2 packages

NVDimagemagick/imagemagick7.0.8-617.0.9-7

Patches

🔴Vulnerability Details

1
GHSA
GHSA-x77f-4pxj-9mvh: In ImageMagick 72022-05-24

📋Vendor Advisories

2
Red Hat
ImageMagick: use-after-free in MngInfoDiscardObject in coders/png.c2019-12-23
Debian
CVE-2019-19952: imagemagick - In ImageMagick 7.0.9-7 Q16, there is a use-after-free in the function MngInfoDis...2019

💬Community

3
Bugzilla
CVE-2019-19952 ImageMagick: use-after-free in MngInfoDiscardObject in coders/png.c [epel-8]2020-01-17
Bugzilla
CVE-2019-19952 ImageMagick: use-after-free in MngInfoDiscardObject in coders/png.c2020-01-17
Bugzilla
CVE-2019-19952 ImageMagick: use-after-free in MngInfoDiscardObject in coders/png.c [fedora-all]2020-01-17