Wind River Support Network

HomeDefectsLIN8-10496
Fixed

LIN8-10496 : Security Advisory - libpng - CVE-2019-7317

Created: Feb 14, 2019    Updated: May 15, 2019
Resolved Date: Apr 23, 2019
Found In Version: 8.0.0.29
Fix Version: 8.0.0.30
Severity: Standard
Applicable for: Wind River Linux 8
Component/s: Userspace

Description

png_image_free in png.c in libpng 1.6.36 has a use-after-free because png_image_free_function is called under png_safe_execute.

https://nvd.nist.gov/vuln/detail/CVE-2019-7317

CVEs


Live chat
Online