pngimagefree in png.c in libpng 1.6.x before 1.6.37 has a use-after-free because pngimagefreefunction is called under pngsafe_execute.
[
{
"deprecated": false,
"id": "CVE-2019-7317-777a6825",
"digest": {
"line_hashes": [
"4483812120425865394765832017743841760",
"295930966388919334935205960237712292835",
"117419540564145513858588339867436813964",
"150157320390828655074241172061404527079",
"15219066793749250240221192274865703159",
"256432711195399036927642262353737110687"
],
"threshold": 0.9
},
"signature_version": "v1",
"target": {
"file": "png.c"
},
"source": "https://github.com/pnggroup/libpng/commit/a40189cf881e9f0db80511c382292a5604c3c3d1",
"signature_type": "Line"
},
{
"deprecated": false,
"id": "CVE-2019-7317-83d81dde",
"digest": {
"function_hash": "182119414766575611561000861233124297530",
"length": 481.0
},
"signature_version": "v1",
"target": {
"function": "png_get_copyright",
"file": "png.c"
},
"source": "https://github.com/pnggroup/libpng/commit/a40189cf881e9f0db80511c382292a5604c3c3d1",
"signature_type": "Function"
},
{
"deprecated": false,
"id": "CVE-2019-7317-9bb3b070",
"digest": {
"line_hashes": [
"241838778844194275048866028647484350554"
],
"threshold": 0.9
},
"signature_version": "v1",
"target": {
"file": "pngtest.c"
},
"source": "https://github.com/pnggroup/libpng/commit/a40189cf881e9f0db80511c382292a5604c3c3d1",
"signature_type": "Line"
},
{
"deprecated": false,
"id": "CVE-2019-7317-d09d8970",
"digest": {
"line_hashes": [
"166375070723291529406421301066248769034",
"275647010778297936193963675511576832388",
"256826767335212246520616614652191899280",
"279336807821086835335477021495116274772",
"99841383750098798180616484435499546727",
"159302944862349488787630211743777147289",
"331742628729745467196492355602919503505",
"120425966103587571923372910432028590987"
],
"threshold": 0.9
},
"signature_version": "v1",
"target": {
"file": "png.h"
},
"source": "https://github.com/pnggroup/libpng/commit/a40189cf881e9f0db80511c382292a5604c3c3d1",
"signature_type": "Line"
}
]
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2019-7317.json"
[
{
"deprecated": false,
"id": "CVE-2019-7317-dfd9b952",
"digest": {
"function_hash": "207208958033309643961658472027306269514",
"length": 1650.0
},
"signature_version": "v1",
"target": {
"function": "LZMADecode",
"file": "libtiff/tif_lzma.c"
},
"source": "https://gitlab.com/libtiff/libtiff@f7b79dc7dc86ccbaabe9882e2b9ffa5ee8dac917",
"signature_type": "Function"
},
{
"deprecated": false,
"id": "CVE-2019-7317-ff63d6e8",
"digest": {
"line_hashes": [
"83735383308701105806633254192405515516",
"297151727776609117273041335871543415477",
"83489008549350845020780847220869080280",
"109231922170225855438601431601770869641",
"237257911720793150025722719320423673589"
],
"threshold": 0.9
},
"signature_version": "v1",
"target": {
"file": "libtiff/tif_lzma.c"
},
"source": "https://gitlab.com/libtiff/libtiff@f7b79dc7dc86ccbaabe9882e2b9ffa5ee8dac917",
"signature_type": "Line"
}
]
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2019-7317.json"