CVE-2019-19952
In ImageMagick 7.0.9-7 Q16, there is a use-after-free in the function MngInfoDiscardObject of coders/png.c, related to ReadOneMNGImage.
- Affected products
- Imagemagick
- Imagemagick
- < 7.0.9-7
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 2.2% (81th percentile)
- Weakness
- CWE-416
- NVD status
- Modified
- Published
- 2019-12-24
CVE-2019-19952 at NVD
No indexed exploits for CVE-2019-19952 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2019-19952 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.