CVE-2019-7317

MEDIUMCVSS 5.3/10EPSS 9.39%

Last modified

CVE-2019-7317 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. png_image_free in png.c in libpng 1.6.x before 1.6.37 has a use-after-free because png_image_free_function is called under png_safe_execute.. EPSS estimates a 9.39% chance of exploitation in the next 30 days.

Description

png_image_free in png.c in libpng 1.6.x before 1.6.37 has a use-after-free because png_image_free_function is called under png_safe_execute.

Metrics

CVSS 3.1
5.3/10

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H

EPSS Probability
9.39%

94.8th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersionsUpdate
LibpngLibpng>= 1.6.0, < 1.6.37
DebianDebian Linux8.0
DebianDebian Linux9.0
CanonicalUbuntu Linux16.04
CanonicalUbuntu Linux18.04
CanonicalUbuntu Linux18.10
CanonicalUbuntu Linux19.04
OracleHyperion Infrastructure Technology11.2.6.0
OracleJava Se7u221
OracleJava Se8u212
OracleJdk11.0.3
OracleJdk12.0.1
OracleMysql< 8.0.23
HpXp7 Command View< 8.7.0-00
HpeXp7 Command View Advanced Edition Suite< 8.7.0-00
MozillaFirefoxAll versions
MozillaThunderbirdAll versions
OpensuseLeap15.0
OpensuseLeap15.1
OpensuseLeap42.3
OpensusePackage HubAll versions
NetappActive Iq Unified Manager< 9.6
NetappActive Iq Unified Manager9.6
NetappCloud BackupAll versions
NetappE-Series Santricity ManagementAll versions
NetappE-Series Santricity Storage Manager< 11.53
NetappE-Series Santricity Unified Manager< 3.2
NetappE-Series Santricity Web Services< 4.0
NetappOncommand Insight< 7.3.9
NetappOncommand Workflow Automation< 5.1
NetappPlug-In For Symantec NetbackupAll versions
NetappSnapmanager< 3.4.2
NetappSnapmanager3.4.2P1
NetappSteelstoreAll versions
RedhatSatellite5.8
RedhatEnterprise Linux6.0
RedhatEnterprise Linux7.0
RedhatEnterprise Linux8.0
RedhatEnterprise Linux Desktop6.0
RedhatEnterprise Linux Desktop7.0
RedhatEnterprise Linux For Ibm Z Systems6.0
RedhatEnterprise Linux For Ibm Z Systems7.0
RedhatEnterprise Linux For Ibm Z Systems8.0
RedhatEnterprise Linux For Power Big Endian6.0
RedhatEnterprise Linux For Power Big Endian7.0
RedhatEnterprise Linux For Power Little Endian7.0
RedhatEnterprise Linux For Power Little Endian8.0
RedhatEnterprise Linux For Scientific Computing6.0
RedhatEnterprise Linux For Scientific Computing7.0
RedhatEnterprise Linux Workstation6.0

Showing 50 of 51 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2019-7317?
png_image_free in png.c in libpng 1.6.x before 1.6.37 has a use-after-free because png_image_free_function is called under png_safe_execute.
How severe is CVE-2019-7317?
CVE-2019-7317 has a CVSS score of 5.3/10 (MEDIUM severity). The EPSS model estimates a 9.39% probability of exploitation in the next 30 days.
How do I fix CVE-2019-7317?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2019-7317?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST