CVE-2019-7317 - CVE House
Back to Database
Status published Unknown CVE-2019-7317

png_image_free in png.c in libpng 1.6.x before 1.6.37 has a...

Vulnerability Description

png_image_free in png.c in libpng 1.6.x before 1.6.37 has a use-after-free because png_image_free_function is called under png_safe_execute.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2019-7317

Credits & Attribution

No credits recorded in the NVD database.

References

Affected Vendor

Affected Software

libpng, debian linux, ubuntu linux, hyperion infrastructure technology, java se, jdk, mysql, xp7 command view, xp7 command view advanced edition suite, firefox, thunderbird, leap, package hub, active iq unified manager, cloud backup, e-series santricity management, e-series santricity storage manager, e-series santricity unified manager, e-series santricity web services, oncommand insight, oncommand workflow automation, plug-in for symantec netbackup, snapmanager, steelstore, satellite, enterprise linux, enterprise linux desktop, enterprise linux for ibm z systems, enterprise linux for power big endian, enterprise linux for power little endian, enterprise linux for scientific computing, enterprise linux workstation
Vulnerable Versions:
1.6.0, 8.0, 9.0, 16.04, 18.04, 18.10, 19.04, 11.2.6.0, 7u221, 8u212, 11.0.3, 12.0.1, 0, 15.0, 15.1, 42.3, 9.6, 3.4.2, 5.8, 6.0, 7.0

Timeline

Official Publish: February 4th, 2019
Last Modified: May 28th, 2026
Added to House: July 20th, 2026

CVSS Vectors

No vector data available

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.