CVE-2019-7317 — Use After Free in Libpng
Severity
5.3MEDIUMNVD
EPSS
0.6%
top 31.54%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 4
Latest updateJan 15
Description
png_image_free in png.c in libpng 1.6.x before 1.6.37 has a use-after-free because png_image_free_function is called under png_safe_execute.
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 1.6 | Impact: 3.6
Affected Packages19 packages
Also affects: Debian Linux 8.0, 9.0, Ubuntu Linux 16.04, 18.04, 18.10, 19.04, Enterprise Linux 6.0, 7.0, 8.0
Patches
🔴Vulnerability Details
6📋Vendor Advisories
11Oracle▶
Oracle Oracle Hyperion Risk Matrix: Installation and Configuration (libpng) — CVE-2019-7317↗2021-10-15
💬Community
9Bugzilla
▶
Bugzilla
▶