MEDIUM · 5.3

CVE-2019-7317

png_image_free in png.c in libpng 1.6.x before 1.6.37 has a use-after-free because png_image_free_function is called under png_safe_execute.

Vulnerability Description

png_image_free in png.c in libpng 1.6.x before 1.6.37 has a use-after-free because png_image_free_function is called under png_safe_execute.

CVSS Score

5.3

MEDIUM

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
LibpngLibpng>= 1.6.0, < 1.6.37
DebianDebian Linux8.0
CanonicalUbuntu Linux16.04
OracleHyperion Infrastructure Technology11.2.6.0
OracleJava Se7u221
OracleJdk11.0.3
OracleMysql< 8.0.23
HpXp7 Command View< 8.7.0-00
HpeXp7 Command View Advanced Edition Suite< 8.7.0-00
MozillaFirefox-
MozillaThunderbird-
OpensuseLeap15.0
OpensusePackage Hub-
SuseLinux Enterprise12.0
NetappActive Iq Unified Manager< 9.6
NetappCloud Backup-
NetappE-Series Santricity Management-
NetappE-Series Santricity Storage Manager< 11.53
NetappE-Series Santricity Unified Manager< 3.2
NetappE-Series Santricity Web Services< 4.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2019-7317?

CVE-2019-7317 is a vulnerability with a CVSS score of 5.3 (MEDIUM). png_image_free in png.c in libpng 1.6.x before 1.6.37 has a use-after-free because png_image_free_function is called under png_safe_execute.

How severe is CVE-2019-7317?

CVE-2019-7317 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2019-7317?

Check the references section above for vendor advisories and patch information. Affected products include: Libpng Libpng, Debian Debian Linux, Canonical Ubuntu Linux, Oracle Hyperion Infrastructure Technology, Oracle Java Se.