CVE-2019-7317

Published Feb 4, 2019

Last updated 10 days ago

Overview

Description
png_image_free in png.c in libpng 1.6.x before 1.6.37 has a use-after-free because png_image_free_function is called under png_safe_execute.
Source
cve@mitre.org
NVD status
Modified
Products
libpng, debian_linux, ubuntu_linux, hyperion_infrastructure_technology, java_se, jdk, mysql, xp7_command_view, xp7_command_view_advanced_edition_suite, firefox, thunderbird, leap, package_hub, active_iq_unified_manager, cloud_backup, e-series_santricity_management, e-series_santricity_storage_manager, e-series_santricity_unified_manager, e-series_santricity_web_services, oncommand_insight, oncommand_workflow_automation, plug-in_for_symantec_netbackup, snapmanager, steelstore, satellite, enterprise_linux, enterprise_linux_desktop, enterprise_linux_for_ibm_z_systems, enterprise_linux_for_power_big_endian, enterprise_linux_for_power_little_endian, enterprise_linux_for_scientific_computing, enterprise_linux_workstation

Risk scores

CVSS 3.1

Type
Primary
Base score
5.3
Impact score
3.6
Exploitability score
1.6
Vector string
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H
Severity
MEDIUM

CVSS 2.0

Type
Primary
Base score
2.6
Impact score
2.9
Exploitability score
4.9
Vector string
AV:N/AC:H/Au:N/C:N/I:N/A:P

Weaknesses

nvd@nist.gov
CWE-416
134c704f-9b21-4f2e-91b3-4a467353bcc0
CWE-416

Social media

Hype score
Not currently trending

Configurations

References

Sources include official advisories and independent security research.