png_image_free in png.c in libpng 1.6.x before 1.6.37 has a use-after-free because png_image_free_function is called under png_safe_execute.
2019-02-04T08:29:00.447
2024-11-21T04:48:00.033
Modified
CVSSv3.1: 5.3 (MEDIUM)
AV:N/AC:H/Au:N/C:N/I:N/A:P
4.9
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | libpng | libpng | < 1.6.37 | Yes |
Operating System | debian | debian_linux | 8.0 | Yes |
Operating System | debian | debian_linux | 9.0 | Yes |
Operating System | canonical | ubuntu_linux | 16.04 | Yes |
Operating System | canonical | ubuntu_linux | 16.04 | Yes |
Operating System | canonical | ubuntu_linux | 18.04 | Yes |
Operating System | canonical | ubuntu_linux | 18.10 | Yes |
Operating System | canonical | ubuntu_linux | 19.04 | Yes |
Application | oracle | hyperion_infrastructure_technology | 11.2.6.0 | Yes |
Application | oracle | java_se | 7u221 | Yes |
Application | oracle | java_se | 8u212 | Yes |
Application | oracle | jdk | 11.0.3 | Yes |
Application | oracle | jdk | 12.0.1 | Yes |
Application | oracle | mysql | < 8.0.23 | Yes |
Application | hp | xp7_command_view | < 8.7.0-00 | Yes |
Application | hpe | xp7_command_view_advanced_edition_suite | < 8.7.0-00 | Yes |
Application | mozilla | firefox | - | Yes |
Application | mozilla | thunderbird | - | Yes |
Operating System | opensuse | leap | 15.0 | Yes |
Operating System | opensuse | leap | 15.1 | Yes |
Operating System | opensuse | leap | 42.3 | Yes |
Application | opensuse | package_hub | - | Yes |
Operating System | suse | linux_enterprise | 12.0 | No |
Application | netapp | active_iq_unified_manager | < 9.6 | Yes |
Application | netapp | active_iq_unified_manager | < 9.6 | Yes |
Application | netapp | active_iq_unified_manager | 9.6 | Yes |
Application | netapp | active_iq_unified_manager | 9.6 | Yes |
Application | netapp | cloud_backup | - | Yes |
Application | netapp | e-series_santricity_management | - | Yes |
Application | netapp | e-series_santricity_storage_manager | < 11.53 | Yes |
Application | netapp | e-series_santricity_unified_manager | < 3.2 | Yes |
Application | netapp | e-series_santricity_web_services | < 4.0 | Yes |
Application | netapp | oncommand_insight | < 7.3.9 | Yes |
Application | netapp | oncommand_workflow_automation | < 5.1 | Yes |
Application | netapp | plug-in_for_symantec_netbackup | - | Yes |
Application | netapp | snapmanager | < 3.4.2 | Yes |
Application | netapp | snapmanager | < 3.4.2 | Yes |
Application | netapp | snapmanager | 3.4.2 | Yes |
Application | netapp | snapmanager | 3.4.2 | Yes |
Application | netapp | steelstore | - | Yes |
Application | redhat | satellite | 5.8 | Yes |
Operating System | redhat | enterprise_linux | 6.0 | Yes |
Operating System | redhat | enterprise_linux | 7.0 | Yes |
Operating System | redhat | enterprise_linux | 8.0 | Yes |
Operating System | redhat | enterprise_linux_desktop | 6.0 | Yes |
Operating System | redhat | enterprise_linux_desktop | 7.0 | Yes |
Operating System | redhat | enterprise_linux_for_ibm_z_systems | 6.0 | Yes |
Operating System | redhat | enterprise_linux_for_ibm_z_systems | 7.0 | Yes |
Operating System | redhat | enterprise_linux_for_ibm_z_systems | 8.0 | Yes |
Operating System | redhat | enterprise_linux_for_power_big_endian | 6.0 | Yes |
Operating System | redhat | enterprise_linux_for_power_big_endian | 7.0 | Yes |
Operating System | redhat | enterprise_linux_for_power_little_endian | 7.0 | Yes |
Operating System | redhat | enterprise_linux_for_power_little_endian | 8.0 | Yes |
Operating System | redhat | enterprise_linux_for_scientific_computing | 6.0 | Yes |
Operating System | redhat | enterprise_linux_for_scientific_computing | 7.0 | Yes |
Operating System | redhat | enterprise_linux_workstation | 6.0 | Yes |
Operating System | redhat | enterprise_linux_workstation | 7.0 | Yes |