pngimagefree in png.c in libpng 1.6.x before 1.6.37 has a use-after-free because pngimagefreefunction is called under pngsafe_execute.
{
"unresolved_ranges": [
{
"cpes": [
"cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:*:*:*:*",
"cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:*",
"cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*",
"cpe:2.3:o:canonical:ubuntu_linux:18.10:*:*:*:*:*:*:*",
"cpe:2.3:o:canonical:ubuntu_linux:19.04:*:*:*:*:*:*:*"
],
"vendor_product": "canonical:ubuntu_linux",
"extracted_events": [
{
"last_affected": "16.04"
},
{
"last_affected": "16.04"
},
{
"last_affected": "18.04"
},
{
"last_affected": "18.10"
},
{
"last_affected": "19.04"
}
],
"source": "CPE_FIELD"
},
{
"cpes": [
"cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*",
"cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*"
],
"vendor_product": "debian:debian_linux",
"extracted_events": [
{
"last_affected": "8.0"
},
{
"last_affected": "9.0"
}
],
"source": "CPE_FIELD"
},
{
"cpes": [
"cpe:2.3:a:hp:xp7_command_view:*:*:*:*:advanced:*:*:*"
],
"vendor_product": "hp:xp7_command_view",
"extracted_events": [
{
"fixed": "8.7.0-00"
}
],
"source": "CPE_FIELD"
},
{
"cpes": [
"cpe:2.3:a:hpe:xp7_command_view_advanced_edition_suite:*:*:*:*:*:*:*:*"
],
"vendor_product": "hpe:xp7_command_view_advanced_edition_suite",
"extracted_events": [
{
"fixed": "8.7.0-00"
}
],
"source": "CPE_FIELD"
},
{
"cpes": [
"cpe:2.3:a:netapp:active_iq_unified_manager:*:*:*:*:*:vmware_vsphere:*:*",
"cpe:2.3:a:netapp:active_iq_unified_manager:*:*:*:*:*:windows:*:*",
"cpe:2.3:a:netapp:active_iq_unified_manager:9.6:*:*:*:*:vmware_vsphere:*:*",
"cpe:2.3:a:netapp:active_iq_unified_manager:9.6:*:*:*:*:windows:*:*"
],
"vendor_product": "netapp:active_iq_unified_manager",
"extracted_events": [
{
"fixed": "9.6"
},
{
"fixed": "9.6"
},
{
"last_affected": "9.6"
},
{
"last_affected": "9.6"
}
],
"source": "CPE_FIELD"
},
{
"cpes": [
"cpe:2.3:a:netapp:e-series_santricity_storage_manager:*:*:*:*:*:*:*:*"
],
"vendor_product": "netapp:e-series_santricity_storage_manager",
"extracted_events": [
{
"fixed": "11.53"
}
],
"source": "CPE_FIELD"
},
{
"cpes": [
"cpe:2.3:a:netapp:e-series_santricity_unified_manager:*:*:*:*:*:*:*:*"
],
"vendor_product": "netapp:e-series_santricity_unified_manager",
"extracted_events": [
{
"fixed": "3.2"
}
],
"source": "CPE_FIELD"
},
{
"cpes": [
"cpe:2.3:a:netapp:e-series_santricity_web_services:*:*:*:*:*:web_services_proxy:*:*"
],
"vendor_product": "netapp:e-series_santricity_web_services",
"extracted_events": [
{
"fixed": "4.0"
}
],
"source": "CPE_FIELD"
},
{
"cpes": [
"cpe:2.3:a:netapp:oncommand_insight:*:*:*:*:*:*:*:*"
],
"vendor_product": "netapp:oncommand_insight",
"extracted_events": [
{
"fixed": "7.3.9"
}
],
"source": "CPE_FIELD"
},
{
"cpes": [
"cpe:2.3:a:netapp:oncommand_workflow_automation:*:*:*:*:*:*:*:*"
],
"vendor_product": "netapp:oncommand_workflow_automation",
"extracted_events": [
{
"fixed": "5.1"
}
],
"source": "CPE_FIELD"
},
{
"cpes": [
"cpe:2.3:a:netapp:snapmanager:*:*:*:*:*:oracle:*:*",
"cpe:2.3:a:netapp:snapmanager:*:*:*:*:*:sap:*:*",
"cpe:2.3:a:netapp:snapmanager:3.4.2:p1:*:*:*:oracle:*:*",
"cpe:2.3:a:netapp:snapmanager:3.4.2:p1:*:*:*:sap:*:*"
],
"vendor_product": "netapp:snapmanager",
"extracted_events": [
{
"fixed": "3.4.2"
},
{
"fixed": "3.4.2"
},
{
"last_affected": "3.4.2-p1"
},
{
"last_affected": "3.4.2-p1"
}
],
"source": "CPE_FIELD"
},
{
"cpes": [
"cpe:2.3:o:opensuse:leap:15.0:*:*:*:*:*:*:*",
"cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:*",
"cpe:2.3:o:opensuse:leap:42.3:*:*:*:*:*:*:*"
],
"vendor_product": "opensuse:leap",
"extracted_events": [
{
"last_affected": "15.0"
},
{
"last_affected": "15.1"
},
{
"last_affected": "42.3"
}
],
"source": "CPE_FIELD"
},
{
"cpes": [
"cpe:2.3:a:oracle:hyperion_infrastructure_technology:11.2.6.0:*:*:*:*:*:*:*"
],
"vendor_product": "oracle:hyperion_infrastructure_technology",
"extracted_events": [
{
"last_affected": "11.2.6.0"
}
],
"source": "CPE_FIELD"
},
{
"cpes": [
"cpe:2.3:a:oracle:java_se:7u221:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:java_se:8u212:*:*:*:*:*:*:*"
],
"vendor_product": "oracle:java_se",
"extracted_events": [
{
"last_affected": "7u221"
},
{
"last_affected": "8u212"
}
],
"source": "CPE_FIELD"
},
{
"cpes": [
"cpe:2.3:a:oracle:jdk:11.0.3:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:jdk:12.0.1:*:*:*:*:*:*:*"
],
"vendor_product": "oracle:jdk",
"extracted_events": [
{
"last_affected": "11.0.3"
},
{
"last_affected": "12.0.1"
}
],
"source": "CPE_FIELD"
},
{
"cpes": [
"cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*",
"cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*",
"cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*"
],
"vendor_product": "redhat:enterprise_linux",
"extracted_events": [
{
"last_affected": "6.0"
},
{
"last_affected": "7.0"
},
{
"last_affected": "8.0"
}
],
"source": "CPE_FIELD"
},
{
"cpes": [
"cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:*",
"cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:*"
],
"vendor_product": "redhat:enterprise_linux_desktop",
"extracted_events": [
{
"last_affected": "6.0"
},
{
"last_affected": "7.0"
}
],
"source": "CPE_FIELD"
},
{
"cpes": [
"cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems:6.0:*:*:*:*:*:*:*",
"cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems:7.0:*:*:*:*:*:*:*",
"cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems:8.0:*:*:*:*:*:*:*"
],
"vendor_product": "redhat:enterprise_linux_for_ibm_z_systems",
"extracted_events": [
{
"last_affected": "6.0"
},
{
"last_affected": "7.0"
},
{
"last_affected": "8.0"
}
],
"source": "CPE_FIELD"
},
{
"cpes": [
"cpe:2.3:o:redhat:enterprise_linux_for_power_big_endian:6.0:*:*:*:*:*:*:*",
"cpe:2.3:o:redhat:enterprise_linux_for_power_big_endian:7.0:*:*:*:*:*:*:*"
],
"vendor_product": "redhat:enterprise_linux_for_power_big_endian",
"extracted_events": [
{
"last_affected": "6.0"
},
{
"last_affected": "7.0"
}
],
"source": "CPE_FIELD"
},
{
"cpes": [
"cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian:7.0:*:*:*:*:*:*:*",
"cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian:8.0:*:*:*:*:*:*:*"
],
"vendor_product": "redhat:enterprise_linux_for_power_little_endian",
"extracted_events": [
{
"last_affected": "7.0"
},
{
"last_affected": "8.0"
}
],
"source": "CPE_FIELD"
},
{
"cpes": [
"cpe:2.3:o:redhat:enterprise_linux_for_scientific_computing:6.0:*:*:*:*:*:*:*",
"cpe:2.3:o:redhat:enterprise_linux_for_scientific_computing:7.0:*:*:*:*:*:*:*"
],
"vendor_product": "redhat:enterprise_linux_for_scientific_computing",
"extracted_events": [
{
"last_affected": "6.0"
},
{
"last_affected": "7.0"
}
],
"source": "CPE_FIELD"
},
{
"cpes": [
"cpe:2.3:o:redhat:enterprise_linux_workstation:6.0:*:*:*:*:*:*:*",
"cpe:2.3:o:redhat:enterprise_linux_workstation:7.0:*:*:*:*:*:*:*"
],
"vendor_product": "redhat:enterprise_linux_workstation",
"extracted_events": [
{
"last_affected": "6.0"
},
{
"last_affected": "7.0"
}
],
"source": "CPE_FIELD"
},
{
"cpes": [
"cpe:2.3:a:redhat:satellite:5.8:*:*:*:*:*:*:*"
],
"vendor_product": "redhat:satellite",
"extracted_events": [
{
"last_affected": "5.8"
}
],
"source": "CPE_FIELD"
}
]
}{
"cpe": "cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:*",
"source": "CPE_FIELD",
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "8.0.23"
}
]
}[
{
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"4483812120425865394765832017743841760",
"295930966388919334935205960237712292835",
"117419540564145513858588339867436813964",
"150157320390828655074241172061404527079",
"15219066793749250240221192274865703159",
"256432711195399036927642262353737110687"
]
},
"id": "CVE-2019-7317-777a6825",
"signature_version": "v1",
"source": "https://github.com/pnggroup/libpng/commit/a40189cf881e9f0db80511c382292a5604c3c3d1",
"target": {
"file": "png.c"
},
"deprecated": false
},
{
"signature_type": "Function",
"digest": {
"function_hash": "182119414766575611561000861233124297530",
"length": 481.0
},
"id": "CVE-2019-7317-83d81dde",
"signature_version": "v1",
"source": "https://github.com/pnggroup/libpng/commit/a40189cf881e9f0db80511c382292a5604c3c3d1",
"target": {
"function": "png_get_copyright",
"file": "png.c"
},
"deprecated": false
},
{
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"241838778844194275048866028647484350554"
]
},
"id": "CVE-2019-7317-9bb3b070",
"signature_version": "v1",
"source": "https://github.com/pnggroup/libpng/commit/a40189cf881e9f0db80511c382292a5604c3c3d1",
"target": {
"file": "pngtest.c"
},
"deprecated": false
},
{
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"166375070723291529406421301066248769034",
"275647010778297936193963675511576832388",
"256826767335212246520616614652191899280",
"279336807821086835335477021495116274772",
"99841383750098798180616484435499546727",
"159302944862349488787630211743777147289",
"331742628729745467196492355602919503505",
"120425966103587571923372910432028590987"
]
},
"id": "CVE-2019-7317-d09d8970",
"signature_version": "v1",
"source": "https://github.com/pnggroup/libpng/commit/a40189cf881e9f0db80511c382292a5604c3c3d1",
"target": {
"file": "png.h"
},
"deprecated": false
}
]
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2019-7317.json"
"2026-05-18T14:17:50Z"