png_image_free in png.c in libpng 1.6.0 up to 1.6.36 had a use-after-free
because png_image_free_function is called under png_safe_execute
(CVE-2019-7317).
- https://bugs.mageia.org/show_bug.cgi?id=24353
- https://github.com/pnggroup/libpng/issues/275
- https://www.cve.org/CVERecord?id=CVE-2019-7317
- 6/core/libpng-1.6.35-1.1.mga6
Get the latest Linux and open source security news straight to your inbox.