png_image_free in png.c in libpng 1.6.x before 1.6.37 has a use-after-free because png_image_free_function is called under png_safe_execute.

Project Subscriptions

Vendors Products
Canonical Subscribe
Ubuntu Linux Subscribe
Debian Linux Subscribe
Xp7 Command View Subscribe
Xp7 Command View Advanced Edition Suite Subscribe
Mozilla Subscribe
Firefox Subscribe
Thunderbird Subscribe
Active Iq Unified Manager Subscribe
Cloud Backup Subscribe
E-series Santricity Management Subscribe
E-series Santricity Storage Manager Subscribe
E-series Santricity Unified Manager Subscribe
E-series Santricity Web Services Subscribe
Oncommand Insight Subscribe
Oncommand Workflow Automation Subscribe
Plug-in For Symantec Netbackup Subscribe
Snapmanager Subscribe
Steelstore Subscribe
Opensuse Subscribe
Package Hub Subscribe
Hyperion Infrastructure Technology Subscribe
Java Se Subscribe
Enterprise Linux Subscribe
Enterprise Linux Desktop Subscribe
Enterprise Linux For Ibm Z Systems Subscribe
Enterprise Linux For Power Big Endian Subscribe
Enterprise Linux For Power Little Endian Subscribe
Enterprise Linux For Scientific Computing Subscribe
Enterprise Linux Workstation Subscribe
Network Satellite Subscribe
Rhel Extras Subscribe
Satellite Subscribe
Linux Enterprise Subscribe
Advisories
Source ID Title
Debian DLA Debian DLA DLA-1800-1 firefox-esr security update
Debian DLA Debian DLA DLA-1806-1 thunderbird security update
Debian DSA Debian DSA DSA-4435-1 libpng1.6 security update
Debian DSA Debian DSA DSA-4448-1 firefox-esr security update
Debian DSA Debian DSA DSA-4451-1 thunderbird security update
EUVD EUVD EUVD-2019-16860 png_image_free in png.c in libpng 1.6.x before 1.6.37 has a use-after-free because png_image_free_function is called under png_safe_execute.
Ubuntu USN Ubuntu USN USN-3962-1 libpng vulnerability
Ubuntu USN Ubuntu USN USN-3991-1 Firefox vulnerabilities
Ubuntu USN Ubuntu USN USN-3997-1 Thunderbird vulnerabilities
Ubuntu USN Ubuntu USN USN-4080-1 OpenJDK 8 vulnerabilities
Ubuntu USN Ubuntu USN USN-4083-1 OpenJDK 11 vulnerabilities
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

References
Link Providers
http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00002.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00029.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00084.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00038.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00044.html cve-icon cve-icon
http://packetstormsecurity.com/files/152561/Slackware-Security-Advisory-libpng-Updates.html cve-icon cve-icon
http://www.securityfocus.com/bid/108098 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2019:1265 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2019:1267 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2019:1269 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2019:1308 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2019:1309 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2019:1310 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2019:2494 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2019:2495 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2019:2585 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2019:2590 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2019:2592 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2019:2737 cve-icon cve-icon
https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=12803 cve-icon cve-icon
https://github.com/glennrp/libpng/issues/275 cve-icon cve-icon
https://lists.debian.org/debian-lts-announce/2019/05/msg00032.html cve-icon cve-icon
https://lists.debian.org/debian-lts-announce/2019/05/msg00038.html cve-icon cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2019-7317 cve-icon
https://seclists.org/bugtraq/2019/Apr/30 cve-icon cve-icon
https://seclists.org/bugtraq/2019/Apr/36 cve-icon cve-icon
https://seclists.org/bugtraq/2019/May/56 cve-icon cve-icon
https://seclists.org/bugtraq/2019/May/59 cve-icon cve-icon
https://seclists.org/bugtraq/2019/May/67 cve-icon cve-icon
https://security.gentoo.org/glsa/201908-02 cve-icon cve-icon
https://security.netapp.com/advisory/ntap-20190719-0005/ cve-icon cve-icon
https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbst03977en_us cve-icon cve-icon
https://usn.ubuntu.com/3962-1/ cve-icon cve-icon
https://usn.ubuntu.com/3991-1/ cve-icon cve-icon
https://usn.ubuntu.com/3997-1/ cve-icon cve-icon
https://usn.ubuntu.com/4080-1/ cve-icon cve-icon
https://usn.ubuntu.com/4083-1/ cve-icon cve-icon
https://www.cve.org/CVERecord?id=CVE-2019-7317 cve-icon
https://www.debian.org/security/2019/dsa-4435 cve-icon cve-icon
https://www.debian.org/security/2019/dsa-4448 cve-icon cve-icon
https://www.debian.org/security/2019/dsa-4451 cve-icon cve-icon
https://www.oracle.com/security-alerts/cpuApr2021.html cve-icon cve-icon
https://www.oracle.com/security-alerts/cpuoct2021.html cve-icon cve-icon
https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html cve-icon cve-icon
History

Sun, 13 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00486}

epss

{'score': 0.00576}


Mon, 21 Oct 2024 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla firefox
CPEs cpe:2.3:a:mozilla:firefox_esr:-:*:*:*:*:*:*:* cpe:2.3:a:mozilla:firefox:-:*:*:*:*:*:*:*
Vendors & Products Mozilla firefox Esr
Mozilla firefox

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-04T20:46:45.928Z

Reserved: 2019-02-04T00:00:00

Link: CVE-2019-7317

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-02-04T08:29:00.447

Modified: 2024-11-21T04:48:00.033

Link: CVE-2019-7317

cve-icon Redhat

Severity : Low

Publid Date: 2019-01-25T00:00:00Z

Links: CVE-2019-7317 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses