png_image_free in png.c in libpng 1.6.x before 1.6.37 has a use-after-free because png_image_free_function is called under png_safe_execute.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Configuration 4 (hide)
|
Configuration 5 (hide)
|
Configuration 6 (hide)
|
Configuration 7 (hide)
|
Configuration 8 (hide)
AND |
|
Configuration 9 (hide)
|
Configuration 10 (hide)
|
Information
Published : 2019-02-04 00:29
Updated : 2022-05-23 08:02
NVD link : CVE-2019-7317
Mitre link : CVE-2019-7317
JSON object : View
CWE
CWE-416
Use After Free
Products Affected
netapp
- cloud_backup
- e-series_santricity_management
- plug-in_for_symantec_netbackup
- active_iq_unified_manager
- e-series_santricity_unified_manager
- oncommand_insight
- e-series_santricity_storage_manager
- snapmanager
- oncommand_workflow_automation
- steelstore
- e-series_santricity_web_services
mozilla
- firefox_esr
- thunderbird
oracle
- mysql
- jdk
- java_se
- hyperion_infrastructure_technology
libpng
- libpng
canonical
- ubuntu_linux
redhat
- satellite
- enterprise_linux
- enterprise_linux_for_scientific_computing
- enterprise_linux_workstation
- enterprise_linux_desktop
- enterprise_linux_for_power_little_endian
- enterprise_linux_for_ibm_z_systems
- enterprise_linux_for_power_big_endian
hp
- xp7_command_view
suse
- linux_enterprise
debian
- debian_linux
hpe
- xp7_command_view_advanced_edition_suite
opensuse
- package_hub
- leap