CVE-2019-7317
04.02.2019, 08:29
png_image_free in png.c in libpng 1.6.x before 1.6.37 has a use-after-free because png_image_free_function is called under png_safe_execute.Enginsight
| Vendor | Product | Version |
|---|---|---|
| libpng | libpng | 1.6.0 ≤ 𝑥 < 1.6.37 |
| debian | debian_linux | 8.0 |
| debian | debian_linux | 9.0 |
| canonical | ubuntu_linux | 16.04 |
| canonical | ubuntu_linux | 16.04 |
| canonical | ubuntu_linux | 18.04 |
| canonical | ubuntu_linux | 18.10 |
| canonical | ubuntu_linux | 19.04 |
| oracle | hyperion_infrastructure_technology | 11.2.6.0 |
| oracle | jdk | 11.0.3 |
| oracle | jdk | 12.0.1 |
| oracle | mysql | 𝑥 < 8.0.23 |
| hp | xp7_command_view | 𝑥 < 8.7.0-00 |
| hpe | xp7_command_view_advanced_edition_suite | 𝑥 < 8.7.0-00 |
| mozilla | firefox | - |
| mozilla | thunderbird | - |
| opensuse | leap | 15.0 |
| opensuse | leap | 15.1 |
| opensuse | leap | 42.3 |
| opensuse | package_hub | - |
| netapp | active_iq_unified_manager | 𝑥 < 9.6 |
| netapp | active_iq_unified_manager | 𝑥 < 9.6 |
| netapp | active_iq_unified_manager | 9.6 |
| netapp | active_iq_unified_manager | 9.6 |
| netapp | cloud_backup | - |
| netapp | e-series_santricity_management | - |
| netapp | e-series_santricity_storage_manager | 𝑥 < 11.53 |
| netapp | e-series_santricity_unified_manager | 𝑥 < 3.2 |
| netapp | e-series_santricity_web_services | 𝑥 < 4.0 |
| netapp | oncommand_insight | 𝑥 < 7.3.9 |
| netapp | oncommand_workflow_automation | 𝑥 < 5.1 |
| netapp | plug-in_for_symantec_netbackup | - |
| netapp | snapmanager | 𝑥 < 3.4.2 |
| netapp | snapmanager | 𝑥 < 3.4.2 |
| netapp | snapmanager | 3.4.2:p1 |
| netapp | snapmanager | 3.4.2:p1 |
| netapp | steelstore | - |
| redhat | satellite | 5.8 |
| redhat | enterprise_linux | 6.0 |
| redhat | enterprise_linux | 7.0 |
| redhat | enterprise_linux | 8.0 |
| redhat | enterprise_linux_desktop | 6.0 |
| redhat | enterprise_linux_desktop | 7.0 |
| redhat | enterprise_linux_for_ibm_z_systems | 6.0 |
| redhat | enterprise_linux_for_ibm_z_systems | 7.0 |
| redhat | enterprise_linux_for_ibm_z_systems | 8.0 |
| redhat | enterprise_linux_for_power_big_endian | 6.0 |
| redhat | enterprise_linux_for_power_big_endian | 7.0 |
| redhat | enterprise_linux_for_power_little_endian | 7.0 |
| redhat | enterprise_linux_for_power_little_endian | 8.0 |
| redhat | enterprise_linux_for_scientific_computing | 6.0 |
| redhat | enterprise_linux_for_scientific_computing | 7.0 |
| redhat | enterprise_linux_workstation | 6.0 |
| redhat | enterprise_linux_workstation | 7.0 |
𝑥
= Vulnerable software versions
Debian Releases
Debian Product | |||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| firefox |
| ||||||||||||||
| firefox-esr |
| ||||||||||||||
| libpng1.6 |
| ||||||||||||||
| thunderbird |
|
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| firefox |
| ||||||||||||||||||||||||||||||
| libpng |
| ||||||||||||||||||||||||||||||
| libpng1.6 |
| ||||||||||||||||||||||||||||||
| openjdk-12 |
| ||||||||||||||||||||||||||||||
| openjdk-8 |
| ||||||||||||||||||||||||||||||
| openjdk-9 |
| ||||||||||||||||||||||||||||||
| openjdk-lts |
| ||||||||||||||||||||||||||||||
| thunderbird |
|
Common Weakness Enumeration
References