First published: Tue Dec 24 2019(Updated: )
In ImageMagick 7.0.9-7 Q16, there is a use-after-free in the function MngInfoDiscardObject of coders/png.c, related to ReadOneMNGImage.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ImageMagick ImageMagick | >=7.0.8-61<7.0.9-7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-19952 is classified as a high-severity vulnerability due to its potential for remote code execution.
To fix CVE-2019-19952, upgrade ImageMagick to a version later than 7.0.9-7.
CVE-2019-19952 affects systems running ImageMagick versions from 7.0.8-61 up to 7.0.9-7.
CVE-2019-19952 involves a use-after-free vulnerability in the ReadOneMNGImage function.
Yes, CVE-2019-19952 can be exploited remotely, allowing attackers to execute code on affected systems.