CVE-2019-19952: ImageMagick
Critical severity, CVSS 9.8. EPSS: 2.2% chance of exploitation in the next 30 days.
In ImageMagick 7.0.9-7 Q16, there is a use-after-free in the function MngInfoDiscardObject of coders/png.c, related to ReadOneMNGImage.
Affected products
- ImageMagick ImageMagick: from 7.0.8-61, before 7.0.9-7 (fixed in 7.0.9-7)
Published 2019-12-24. Last modified 2026-06-17.