CVE-2019-7317
MEDIUMCVSS 5.3/10EPSS 9.39%
Last modified
CVE-2019-7317 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. png_image_free in png.c in libpng 1.6.x before 1.6.37 has a use-after-free because png_image_free_function is called under png_safe_execute.. EPSS estimates a 9.39% chance of exploitation in the next 30 days.
Description
png_image_free in png.c in libpng 1.6.x before 1.6.37 has a use-after-free because png_image_free_function is called under png_safe_execute.
Metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Libpng | Libpng | >= 1.6.0, < 1.6.37 | — |
| Debian | Debian Linux | 8.0 | — |
| Debian | Debian Linux | 9.0 | — |
| Canonical | Ubuntu Linux | 16.04 | — |
| Canonical | Ubuntu Linux | 18.04 | — |
| Canonical | Ubuntu Linux | 18.10 | — |
| Canonical | Ubuntu Linux | 19.04 | — |
| Oracle | Hyperion Infrastructure Technology | 11.2.6.0 | — |
| Oracle | Java Se | 7u221 | — |
| Oracle | Java Se | 8u212 | — |
| Oracle | Jdk | 11.0.3 | — |
| Oracle | Jdk | 12.0.1 | — |
| Oracle | Mysql | < 8.0.23 | — |
| Hp | Xp7 Command View | < 8.7.0-00 | — |
| Hpe | Xp7 Command View Advanced Edition Suite | < 8.7.0-00 | — |
| Mozilla | Firefox | All versions | — |
| Mozilla | Thunderbird | All versions | — |
| Opensuse | Leap | 15.0 | — |
| Opensuse | Leap | 15.1 | — |
| Opensuse | Leap | 42.3 | — |
| Opensuse | Package Hub | All versions | — |
| Netapp | Active Iq Unified Manager | < 9.6 | — |
| Netapp | Active Iq Unified Manager | 9.6 | — |
| Netapp | Cloud Backup | All versions | — |
| Netapp | E-Series Santricity Management | All versions | — |
| Netapp | E-Series Santricity Storage Manager | < 11.53 | — |
| Netapp | E-Series Santricity Unified Manager | < 3.2 | — |
| Netapp | E-Series Santricity Web Services | < 4.0 | — |
| Netapp | Oncommand Insight | < 7.3.9 | — |
| Netapp | Oncommand Workflow Automation | < 5.1 | — |
| Netapp | Plug-In For Symantec Netbackup | All versions | — |
| Netapp | Snapmanager | < 3.4.2 | — |
| Netapp | Snapmanager | 3.4.2 | P1 |
| Netapp | Steelstore | All versions | — |
| Redhat | Satellite | 5.8 | — |
| Redhat | Enterprise Linux | 6.0 | — |
| Redhat | Enterprise Linux | 7.0 | — |
| Redhat | Enterprise Linux | 8.0 | — |
| Redhat | Enterprise Linux Desktop | 6.0 | — |
| Redhat | Enterprise Linux Desktop | 7.0 | — |
| Redhat | Enterprise Linux For Ibm Z Systems | 6.0 | — |
| Redhat | Enterprise Linux For Ibm Z Systems | 7.0 | — |
| Redhat | Enterprise Linux For Ibm Z Systems | 8.0 | — |
| Redhat | Enterprise Linux For Power Big Endian | 6.0 | — |
| Redhat | Enterprise Linux For Power Big Endian | 7.0 | — |
| Redhat | Enterprise Linux For Power Little Endian | 7.0 | — |
| Redhat | Enterprise Linux For Power Little Endian | 8.0 | — |
| Redhat | Enterprise Linux For Scientific Computing | 6.0 | — |
| Redhat | Enterprise Linux For Scientific Computing | 7.0 | — |
| Redhat | Enterprise Linux Workstation | 6.0 | — |
Showing 50 of 51 affected configurations. See NVD for the full list.
References
- http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00002.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00029.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00084.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00038.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00044.htmlMailing List, Third Party Advisory
- http://packetstormsecurity.com/files/152561/Slackware-Security-Advisory-libpng-Updates.htmlThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/108098Not Applicable, Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2019:1265Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:1267Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:1269Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:1308Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:1309Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:1310Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2494Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2495Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2585Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2590Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2592Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2737Third Party Advisory
- https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=12803Issue Tracking, Mailing List, Third Party Advisory
- https://github.com/glennrp/libpng/issues/275Exploit, Issue Tracking, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/05/msg00032.htmlMailing List, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/05/msg00038.htmlMailing List, Third Party Advisory
- https://seclists.org/bugtraq/2019/Apr/30Issue Tracking, Mailing List, Third Party Advisory
- https://seclists.org/bugtraq/2019/Apr/36Issue Tracking, Mailing List, Third Party Advisory
- https://seclists.org/bugtraq/2019/May/56Issue Tracking, Mailing List, Third Party Advisory
- https://seclists.org/bugtraq/2019/May/59Issue Tracking, Mailing List, Third Party Advisory
- https://seclists.org/bugtraq/2019/May/67Issue Tracking, Mailing List, Third Party Advisory
- https://security.gentoo.org/glsa/201908-02Third Party Advisory
- https://security.netapp.com/advisory/ntap-20190719-0005/Third Party Advisory
- https://usn.ubuntu.com/3962-1/Third Party Advisory
- https://usn.ubuntu.com/3991-1/Third Party Advisory
- https://usn.ubuntu.com/3997-1/Third Party Advisory
- https://usn.ubuntu.com/4080-1/Third Party Advisory
- https://usn.ubuntu.com/4083-1/Third Party Advisory
- https://www.debian.org/security/2019/dsa-4435Third Party Advisory
- https://www.debian.org/security/2019/dsa-4448Third Party Advisory
- https://www.debian.org/security/2019/dsa-4451Third Party Advisory
- https://www.oracle.com/security-alerts/cpuApr2021.htmlThird Party Advisory
- https://www.oracle.com/security-alerts/cpuoct2021.htmlThird Party Advisory
- https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.htmlPatch, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00002.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00029.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00084.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00038.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00044.htmlMailing List, Third Party Advisory
- http://packetstormsecurity.com/files/152561/Slackware-Security-Advisory-libpng-Updates.htmlThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/108098Not Applicable, Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2019:1265Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:1267Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:1269Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:1308Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:1309Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:1310Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2494Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2495Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2585Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2590Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2592Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2737Third Party Advisory
- https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=12803Issue Tracking, Mailing List, Third Party Advisory
- https://github.com/glennrp/libpng/issues/275Exploit, Issue Tracking, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/05/msg00032.htmlMailing List, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/05/msg00038.htmlMailing List, Third Party Advisory
- https://seclists.org/bugtraq/2019/Apr/30Issue Tracking, Mailing List, Third Party Advisory
- https://seclists.org/bugtraq/2019/Apr/36Issue Tracking, Mailing List, Third Party Advisory
- https://seclists.org/bugtraq/2019/May/56Issue Tracking, Mailing List, Third Party Advisory
- https://seclists.org/bugtraq/2019/May/59Issue Tracking, Mailing List, Third Party Advisory
- https://seclists.org/bugtraq/2019/May/67Issue Tracking, Mailing List, Third Party Advisory
- https://security.gentoo.org/glsa/201908-02Third Party Advisory
- https://security.netapp.com/advisory/ntap-20190719-0005/Third Party Advisory
- https://usn.ubuntu.com/3962-1/Third Party Advisory
- https://usn.ubuntu.com/3991-1/Third Party Advisory
- https://usn.ubuntu.com/3997-1/Third Party Advisory
- https://usn.ubuntu.com/4080-1/Third Party Advisory
- https://usn.ubuntu.com/4083-1/Third Party Advisory
- https://www.debian.org/security/2019/dsa-4435Third Party Advisory
- https://www.debian.org/security/2019/dsa-4448Third Party Advisory
- https://www.debian.org/security/2019/dsa-4451Third Party Advisory
- https://www.oracle.com/security-alerts/cpuApr2021.htmlThird Party Advisory
- https://www.oracle.com/security-alerts/cpuoct2021.htmlThird Party Advisory
- https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.htmlPatch, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-7317?
png_image_free in png.c in libpng 1.6.x before 1.6.37 has a use-after-free because png_image_free_function is called under png_safe_execute.
How severe is CVE-2019-7317?
CVE-2019-7317 has a CVSS score of 5.3/10 (MEDIUM severity). The EPSS model estimates a 9.39% probability of exploitation in the next 30 days.
How do I fix CVE-2019-7317?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
Are you affected by CVE-2019-7317?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
