CVE-2019-7317

LOW

Description

png_image_free in png.c in libpng 1.6.x before 1.6.37 has a use-after-free because png_image_free_function is called under png_safe_execute.

References

http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00002.html

http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00029.html

http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00084.html

http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00038.html

http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00044.html

http://packetstormsecurity.com/files/152561/Slackware-Security-Advisory-libpng-Updates.html

http://www.securityfocus.com/bid/108098

https://access.redhat.com/errata/RHSA-2019:1265

https://access.redhat.com/errata/RHSA-2019:1267

https://access.redhat.com/errata/RHSA-2019:1269

https://access.redhat.com/errata/RHSA-2019:1308

https://access.redhat.com/errata/RHSA-2019:1309

https://access.redhat.com/errata/RHSA-2019:1310

https://access.redhat.com/errata/RHSA-2019:2494

https://access.redhat.com/errata/RHSA-2019:2495

https://access.redhat.com/errata/RHSA-2019:2585

https://access.redhat.com/errata/RHSA-2019:2590

https://access.redhat.com/errata/RHSA-2019:2592

https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=12803

https://github.com/glennrp/libpng/issues/275

https://lists.debian.org/debian-lts-announce/2019/05/msg00032.html

https://lists.debian.org/debian-lts-announce/2019/05/msg00038.html

https://seclists.org/bugtraq/2019/Apr/30

https://seclists.org/bugtraq/2019/Apr/36

https://seclists.org/bugtraq/2019/May/56

https://seclists.org/bugtraq/2019/May/59

https://seclists.org/bugtraq/2019/May/67

https://security.gentoo.org/glsa/201908-02

https://security.netapp.com/advisory/ntap-20190719-0005/

https://usn.ubuntu.com/3962-1/

https://usn.ubuntu.com/3991-1/

https://usn.ubuntu.com/3997-1/

https://usn.ubuntu.com/4080-1/

https://usn.ubuntu.com/4083-1/

https://www.debian.org/security/2019/dsa-4435

https://www.debian.org/security/2019/dsa-4448

https://www.debian.org/security/2019/dsa-4451

https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html

Details

Source: MITRE

Published: 2019-02-04

Updated: 2019-08-01

Type: CWE-416

Risk Information

CVSS v2.0

Base Score: 2.6

Vector: AV:N/AC:H/Au:N/C:N/I:N/A:P

Impact Score: 2.9

Exploitability Score: 4.9

Severity: LOW

CVSS v3.0

Base Score: 5.3

Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H

Impact Score: 3.6

Exploitability Score: 1.6

Severity: MEDIUM