CPANSA-Image-PNG-Simple-2019-7317-libpng: Image-PNG-Simple vulnerability
| Publisher | giterlizzi | Document category | csaf_security_advisory |
|---|---|---|---|
| Initial release date | 2019-02-04T00:00:00 | Engine | CSAF Perl Toolkit 0.26 |
| Current release date | 2019-02-04T00:00:00 | Build Date | |
| Current version | 1 | Status | final |
| CVSS v3.1 Base Score | 5.3 | Severity | Medium |
| Original language | Language | en | |
| Also referred to | |||
Vulnerability Description
png_image_free in png.c in libpng 1.6.x before 1.6.37 has a use-after-free because png_image_free_function is called under png_safe_execute.
Vulnerabilities
CVE-2019-7317
Vulnerability Descriptionpng_image_free in png.c in libpng 1.6.x before 1.6.37 has a use-after-free because png_image_free_function is called under png_safe_execute.
| Weakness | CWE-416 : Use After Free |
|---|
Product status
Known affected
| Product | Score | ||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Image-PNG-Simple greater than or equal 0.01 and less than or equal 0.07 |
|
giterlizzi
Namespace: https://github.com/giterlizzi/
gdt@cpan.org
References
- CPANSA-Image-PNG-Simple-2019-7317-libpng JSON self
https://raw.githubusercontent.com/giterlizzi/perl-CPANSA-CSAF/develop/csaf/white/2019/cpansa-image-png-simple-2019-7317-libpng.json - https://github.com/glennrp/libpng/issues/275 external
https://github.com/glennrp/libpng/issues/275 - https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=12803 external
https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=12803 - https://seclists.org/bugtraq/2019/Apr/30 external
https://seclists.org/bugtraq/2019/Apr/30 - http://packetstormsecurity.com/files/152561/Slackware-Security-Advisory-libpng-Updates.html external
http://packetstormsecurity.com/files/152561/Slackware-Security-Advisory-libpng-Updates.html - https://www.debian.org/security/2019/dsa-4435 external
https://www.debian.org/security/2019/dsa-4435 - https://seclists.org/bugtraq/2019/Apr/36 external
https://seclists.org/bugtraq/2019/Apr/36 - https://usn.ubuntu.com/3962-1/ external
https://usn.ubuntu.com/3962-1/ - https://usn.ubuntu.com/3991-1/ external
https://usn.ubuntu.com/3991-1/ - https://seclists.org/bugtraq/2019/May/56 external
https://seclists.org/bugtraq/2019/May/56 - https://seclists.org/bugtraq/2019/May/59 external
https://seclists.org/bugtraq/2019/May/59 - https://www.debian.org/security/2019/dsa-4448 external
https://www.debian.org/security/2019/dsa-4448 - https://lists.debian.org/debian-lts-announce/2019/05/msg00032.html external
https://lists.debian.org/debian-lts-announce/2019/05/msg00032.html - https://access.redhat.com/errata/RHSA-2019:1265 external
https://access.redhat.com/errata/RHSA-2019:1265 - https://access.redhat.com/errata/RHSA-2019:1269 external
https://access.redhat.com/errata/RHSA-2019:1269 - https://access.redhat.com/errata/RHSA-2019:1267 external
https://access.redhat.com/errata/RHSA-2019:1267 - https://www.debian.org/security/2019/dsa-4451 external
https://www.debian.org/security/2019/dsa-4451 - https://seclists.org/bugtraq/2019/May/67 external
https://seclists.org/bugtraq/2019/May/67 - https://lists.debian.org/debian-lts-announce/2019/05/msg00038.html external
https://lists.debian.org/debian-lts-announce/2019/05/msg00038.html - https://usn.ubuntu.com/3997-1/ external
https://usn.ubuntu.com/3997-1/ - http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00002.html external
http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00002.html - https://access.redhat.com/errata/RHSA-2019:1310 external
https://access.redhat.com/errata/RHSA-2019:1310 - https://access.redhat.com/errata/RHSA-2019:1309 external
https://access.redhat.com/errata/RHSA-2019:1309 - https://access.redhat.com/errata/RHSA-2019:1308 external
https://access.redhat.com/errata/RHSA-2019:1308 - http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00029.html external
http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00029.html - http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00084.html external
http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00084.html - http://www.securityfocus.com/bid/108098 external
http://www.securityfocus.com/bid/108098 - https://security.netapp.com/advisory/ntap-20190719-0005/ external
https://security.netapp.com/advisory/ntap-20190719-0005/ - https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html external
https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html - https://usn.ubuntu.com/4080-1/ external
https://usn.ubuntu.com/4080-1/ - https://usn.ubuntu.com/4083-1/ external
https://usn.ubuntu.com/4083-1/ - https://security.gentoo.org/glsa/201908-02 external
https://security.gentoo.org/glsa/201908-02 - https://access.redhat.com/errata/RHSA-2019:2494 external
https://access.redhat.com/errata/RHSA-2019:2494 - https://access.redhat.com/errata/RHSA-2019:2495 external
https://access.redhat.com/errata/RHSA-2019:2495 - http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00044.html external
http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00044.html - http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00038.html external
http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00038.html - https://access.redhat.com/errata/RHSA-2019:2585 external
https://access.redhat.com/errata/RHSA-2019:2585 - https://access.redhat.com/errata/RHSA-2019:2590 external
https://access.redhat.com/errata/RHSA-2019:2590 - https://access.redhat.com/errata/RHSA-2019:2592 external
https://access.redhat.com/errata/RHSA-2019:2592 - https://access.redhat.com/errata/RHSA-2019:2737 external
https://access.redhat.com/errata/RHSA-2019:2737 - https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbst03977en_us external
https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbst03977en_us - https://www.oracle.com/security-alerts/cpuApr2021.html external
https://www.oracle.com/security-alerts/cpuApr2021.html - https://www.oracle.com/security-alerts/cpuoct2021.html external
https://www.oracle.com/security-alerts/cpuoct2021.html - CVE-2019-7317 (NVD) external
https://nvd.nist.gov/vuln/detail/CVE-2019-7317
Revision history
| Version | Date of the revision | Summary of the revision |
|---|---|---|
| 1 | Mon Feb 4 00:00:00 2019 | First release |
Sharing rules
TLP:WHITE
For the TLP version see: https://www.first.org/tlp/