In ImageMagick 7.0.9-7 Q16, there is a use-after-free in the function MngInfoDiscardObject of coders/png.c, related to ReadOneMNGImage.
References
Link | Resource |
---|---|
https://github.com/ImageMagick/ImageMagick/issues/1791 | Exploit Patch Third Party Advisory |
Configurations
Information
Published : 2019-12-23 17:15
Updated : 2020-01-02 07:46
NVD link : CVE-2019-19952
Mitre link : CVE-2019-19952
JSON object : View
CWE
CWE-416
Use After Free
Products Affected
imagemagick
- imagemagick