CVE-2019-19952: Use After Free
Published Dec 24, 2019
·Updated
In ImageMagick 7.0.9-7 Q16, there is a use-after-free in the function MngInfoDiscardObject of coders/png.c, related to ReadOneMNGImage.
Affected Software
1 affected component
ImageMagick>=7.0.8-61<7.0.9-7
Remediation
Patch Available
Event History
Dec 24, 2019
CVE Published
via MITRE·12:06 AM
Data Sourced
via MITRE·12:06 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-19952?
CVE-2019-19952 is classified as a high-severity vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2019-19952?
To fix CVE-2019-19952, upgrade ImageMagick to a version later than 7.0.9-7.
3
What types of systems are affected by CVE-2019-19952?
CVE-2019-19952 affects systems running ImageMagick versions from 7.0.8-61 up to 7.0.9-7.
4
What is the nature of the vulnerability in CVE-2019-19952?
CVE-2019-19952 involves a use-after-free vulnerability in the ReadOneMNGImage function.
5
Can CVE-2019-19952 be exploited remotely?
Yes, CVE-2019-19952 can be exploited remotely, allowing attackers to execute code on affected systems.