png_image_free in png.c in libpng 1.6.x before 1.6.37 has a use-after-free because png_image_free_function is called under png_safe_execute.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Configuration 4 (hide)
|
Configuration 5 (hide)
|
Configuration 6 (hide)
|
Configuration 7 (hide)
|
Configuration 8 (hide)
AND |
|
Configuration 9 (hide)
|
Configuration 10 (hide)
|
History
21 Oct 2024, 13:55
Type | Values Removed | Values Added |
---|---|---|
First Time |
Mozilla firefox
|
|
CPE | cpe:2.3:a:mozilla:firefox:-:*:*:*:*:*:*:* |
Information
Published : 2019-02-04 08:29
Updated : 2024-10-21 13:55
NVD link : CVE-2019-7317
Mitre link : CVE-2019-7317
CVE.ORG link : CVE-2019-7317
JSON object : View
Products Affected
netapp
- plug-in_for_symantec_netbackup
- e-series_santricity_web_services
- steelstore
- oncommand_insight
- snapmanager
- cloud_backup
- e-series_santricity_storage_manager
- e-series_santricity_management
- active_iq_unified_manager
- e-series_santricity_unified_manager
- oncommand_workflow_automation
redhat
- enterprise_linux_for_scientific_computing
- enterprise_linux_desktop
- enterprise_linux_for_power_little_endian
- enterprise_linux
- enterprise_linux_for_ibm_z_systems
- enterprise_linux_for_power_big_endian
- enterprise_linux_workstation
- satellite
oracle
- jdk
- java_se
- mysql
- hyperion_infrastructure_technology
mozilla
- thunderbird
- firefox
hp
- xp7_command_view
libpng
- libpng
hpe
- xp7_command_view_advanced_edition_suite
canonical
- ubuntu_linux
opensuse
- leap
- package_hub
suse
- linux_enterprise
debian
- debian_linux
CWE
CWE-416
Use After Free