CVE-2019-7317
png_image_free in png.c in libpng 1.6.x before 1.6.37 has a use-after-free because png_image_free_function is called under png_safe_execute.
- Libpng
- < 1.6.37
- Fix
- Available
- CVSS 3.1
- 5.3 MEDIUM
- EPSS
- 9.4% (95th percentile)
- Weakness
- CWE-416
- NVD status
- Modified
- Published
- 2019-02-04
CVE-2019-7317 at NVD
2 known exploits for CVE-2019-7317
Proof-of-concept code and exploit modules indexed by Sploitus