First published: Mon Feb 04 2019(Updated: )
A use-after-free vulnerability was discovered in the png_image_free function in the libpng library. This could lead to denial of service or a potentially exploitable crash when a malformed image is processed.
Credit: cve@mitre.org cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/libpng1.6 | <=1.6.28-1<=1.6.36-3<=1.6.36-2 | 1.6.36-4 1.6.28-1+deb9u1 |
Mozilla Thunderbird | <60.7 | 60.7 |
Mozilla Firefox ESR | <60.7 | 60.7 |
Mozilla Firefox | <67 | 67 |
IBM Cognos Analytics | <=12.0.0-12.0.3 | |
IBM Cognos Analytics | <=11.2.0-11.2.4 FP4 | |
debian/firefox | 135.0-1 | |
debian/firefox-esr | 115.14.0esr-1~deb11u1 128.7.0esr-1~deb11u1 128.5.0esr-1~deb12u1 128.7.0esr-1~deb12u1 128.7.0esr-1 | |
debian/libpng1.6 | 1.6.37-3 1.6.39-2 1.6.46-4 | |
debian/thunderbird | 1:115.12.0-1~deb11u1 1:128.7.0esr-1~deb11u1 1:128.5.0esr-1~deb12u1 1:128.7.0esr-1~deb12u1 1:128.6.0esr-1 | |
libpng | >=1.6.0<1.6.37 | |
Debian | =8.0 | |
Debian | =9.0 | |
Ubuntu | =16.04 | |
Ubuntu | =16.04 | |
Ubuntu | =18.04 | |
Ubuntu | =18.10 | |
Ubuntu | =19.04 | |
oracle hyperion infrastructure technology | =11.2.6.0 | |
Oracle Java | =7u221 | |
Oracle Java | =8u212 | |
Oracle JDK 6 | =11.0.3 | |
Oracle JDK 6 | =12.0.1 | |
MySQL | <8.0.23 | |
HP P9000 Command View Advanced Edition Software | <8.7.0-00 | |
HP XP7 Command View Advanced Edition Suite | <8.7.0-00 | |
Mozilla Firefox | ||
Mozilla Thunderbird | ||
openSUSE | =15.0 | |
openSUSE | =15.1 | |
openSUSE | =42.3 | |
All of | ||
openSUSE Package Hub | ||
SUSE Linux Enterprise Server | =12.0 | |
NetApp Active IQ Unified Manager for VMware vSphere | <9.6 | |
netapp active iq unified manager windows | <9.6 | |
NetApp Active IQ Unified Manager for VMware vSphere | =9.6 | |
netapp active iq unified manager windows | =9.6 | |
netapp cloud backup | ||
NetApp E-Series SANtricity Management for VMware vCenter | ||
netapp e-series santricity storage manager | <11.53 | |
netapp e-series santricity unified manager | <3.2 | |
netapp e-series santricity Web services Web services proxy | <4.0 | |
NetApp OnCommand Insight | <7.3.9 | |
NetApp OnCommand Workflow Automation | <5.1 | |
netapp plug-in for symantec netbackup | ||
netapp snapmanager Oracle | <3.4.2 | |
netapp snapmanager sap | <3.4.2 | |
netapp snapmanager Oracle | =3.4.2-p1 | |
netapp snapmanager sap | =3.4.2-p1 | |
NetApp SteelStore | ||
redhat satellite | =5.8 | |
Red Hat Enterprise Linux | =6.0 | |
Red Hat Enterprise Linux | =7.0 | |
Red Hat Enterprise Linux | =8.0 | |
redhat enterprise Linux desktop | =6.0 | |
redhat enterprise Linux desktop | =7.0 | |
redhat enterprise Linux for ibm z systems | =6.0 | |
redhat enterprise Linux for ibm z systems | =7.0 | |
redhat enterprise Linux for ibm z systems | =8.0 | |
redhat enterprise Linux for power big endian | =6.0 | |
redhat enterprise Linux for power big endian | =7.0 | |
redhat enterprise Linux for power little endian | =7.0 | |
redhat enterprise Linux for power little endian | =8.0 | |
redhat enterprise Linux for scientific computing | =6.0 | |
redhat enterprise Linux for scientific computing | =7.0 | |
redhat enterprise Linux workstation | =6.0 | |
redhat enterprise Linux workstation | =7.0 | |
Mozilla Firefox ESR | ||
openSUSE Package Hub | ||
SUSE Linux Enterprise Server | =12.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
(Found alongside the following vulnerabilities)
CVE-2019-7317 is categorized as a use-after-free vulnerability that could lead to denial of service or crashes.
CVE-2019-7317 affects libpng versions prior to 1.6.37.
To resolve CVE-2019-7317, upgrade libpng to version 1.6.37 or later.
CVE-2019-7317 impacts multiple products including Mozilla Firefox, Thunderbird, and various versions of libpng.
Yes, CVE-2019-7317 is potentially exploitable in production environments when handling malformed images.