png_image_free in png.c in libpng 1.6.x before 1.6.37 has a use-after-free because png_image_free_function is called under png_safe_execute.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Configuration 4 (hide)
|
Configuration 5 (hide)
|
Configuration 6 (hide)
|
Configuration 7 (hide)
|
Configuration 8 (hide)
AND |
|
Configuration 9 (hide)
|
Configuration 10 (hide)
|
History
21 Nov 2024, 04:48
Type | Values Removed | Values Added |
---|---|---|
References | () http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00002.html - Third Party Advisory | |
References | () http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00029.html - Mailing List, Third Party Advisory | |
References | () http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00084.html - Mailing List, Third Party Advisory | |
References | () http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00038.html - Mailing List, Third Party Advisory | |
References | () http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00044.html - Mailing List, Third Party Advisory | |
References | () http://packetstormsecurity.com/files/152561/Slackware-Security-Advisory-libpng-Updates.html - Third Party Advisory, VDB Entry | |
References | () http://www.securityfocus.com/bid/108098 - Not Applicable, Third Party Advisory, VDB Entry | |
References | () https://access.redhat.com/errata/RHSA-2019:1265 - Third Party Advisory | |
References | () https://access.redhat.com/errata/RHSA-2019:1267 - Third Party Advisory | |
References | () https://access.redhat.com/errata/RHSA-2019:1269 - Third Party Advisory | |
References | () https://access.redhat.com/errata/RHSA-2019:1308 - Third Party Advisory | |
References | () https://access.redhat.com/errata/RHSA-2019:1309 - Third Party Advisory | |
References | () https://access.redhat.com/errata/RHSA-2019:1310 - Third Party Advisory | |
References | () https://access.redhat.com/errata/RHSA-2019:2494 - Third Party Advisory | |
References | () https://access.redhat.com/errata/RHSA-2019:2495 - Third Party Advisory | |
References | () https://access.redhat.com/errata/RHSA-2019:2585 - Third Party Advisory | |
References | () https://access.redhat.com/errata/RHSA-2019:2590 - Third Party Advisory | |
References | () https://access.redhat.com/errata/RHSA-2019:2592 - Third Party Advisory | |
References | () https://access.redhat.com/errata/RHSA-2019:2737 - Third Party Advisory | |
References | () https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=12803 - Issue Tracking, Mailing List, Third Party Advisory | |
References | () https://github.com/glennrp/libpng/issues/275 - Exploit, Issue Tracking, Third Party Advisory | |
References | () https://lists.debian.org/debian-lts-announce/2019/05/msg00032.html - Mailing List, Third Party Advisory | |
References | () https://lists.debian.org/debian-lts-announce/2019/05/msg00038.html - Mailing List, Third Party Advisory | |
References | () https://seclists.org/bugtraq/2019/Apr/30 - Issue Tracking, Mailing List, Third Party Advisory | |
References | () https://seclists.org/bugtraq/2019/Apr/36 - Issue Tracking, Mailing List, Third Party Advisory | |
References | () https://seclists.org/bugtraq/2019/May/56 - Issue Tracking, Mailing List, Third Party Advisory | |
References | () https://seclists.org/bugtraq/2019/May/59 - Issue Tracking, Mailing List, Third Party Advisory | |
References | () https://seclists.org/bugtraq/2019/May/67 - Issue Tracking, Mailing List, Third Party Advisory | |
References | () https://security.gentoo.org/glsa/201908-02 - Third Party Advisory | |
References | () https://security.netapp.com/advisory/ntap-20190719-0005/ - Third Party Advisory | |
References | () https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbst03977en_us - Third Party Advisory | |
References | () https://usn.ubuntu.com/3962-1/ - Third Party Advisory | |
References | () https://usn.ubuntu.com/3991-1/ - Third Party Advisory | |
References | () https://usn.ubuntu.com/3997-1/ - Third Party Advisory | |
References | () https://usn.ubuntu.com/4080-1/ - Third Party Advisory | |
References | () https://usn.ubuntu.com/4083-1/ - Third Party Advisory | |
References | () https://www.debian.org/security/2019/dsa-4435 - Third Party Advisory | |
References | () https://www.debian.org/security/2019/dsa-4448 - Third Party Advisory | |
References | () https://www.debian.org/security/2019/dsa-4451 - Third Party Advisory | |
References | () https://www.oracle.com/security-alerts/cpuApr2021.html - Third Party Advisory | |
References | () https://www.oracle.com/security-alerts/cpuoct2021.html - Third Party Advisory | |
References | () https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html - Patch, Third Party Advisory |
21 Oct 2024, 13:55
Type | Values Removed | Values Added |
---|---|---|
First Time |
Mozilla firefox
|
|
CPE | cpe:2.3:a:mozilla:firefox:-:*:*:*:*:*:*:* |
Information
Published : 2019-02-04 08:29
Updated : 2024-11-21 04:48
NVD link : CVE-2019-7317
Mitre link : CVE-2019-7317
CVE.ORG link : CVE-2019-7317
JSON object : View
Products Affected
debian
- debian_linux
netapp
- e-series_santricity_web_services
- steelstore
- active_iq_unified_manager
- e-series_santricity_unified_manager
- snapmanager
- cloud_backup
- e-series_santricity_management
- plug-in_for_symantec_netbackup
- oncommand_workflow_automation
- e-series_santricity_storage_manager
- oncommand_insight
oracle
- java_se
- mysql
- hyperion_infrastructure_technology
- jdk
redhat
- enterprise_linux_for_power_big_endian
- enterprise_linux_for_scientific_computing
- satellite
- enterprise_linux_desktop
- enterprise_linux_for_ibm_z_systems
- enterprise_linux_for_power_little_endian
- enterprise_linux_workstation
- enterprise_linux
canonical
- ubuntu_linux
hpe
- xp7_command_view_advanced_edition_suite
mozilla
- thunderbird
- firefox
opensuse
- package_hub
- leap
hp
- xp7_command_view
suse
- linux_enterprise
libpng
- libpng
CWE
CWE-416
Use After Free