CVE-2018-14048: Medium severity libpng LIBPNG vulnerability
An issue has been found in libpng 1.6.34. It is a SEGV in the function pngfreedata in png.c, related to the recommended error handling for pngreadimage.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/libpng1.6to a version that resolves this vulnerability.Fixed in 1.6.37-3Fixed in 1.6.37-3+deb11u4Fixed in 1.6.39-2+deb12u5Fixed in 1.6.48-1+deb13u5Fixed in 1.6.58-1
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue in libpng?
The vulnerability ID for this issue in libpng is CVE-2018-14048.
What is the severity of CVE-2018-14048?
The severity of CVE-2018-14048 is medium, with a severity value of 6.5.
Which software versions are affected by CVE-2018-14048?
Versions 1.6.34 of libpng, 1.6.0-update201 of Oracle JDK, 1.7.0-update191 of Oracle JDK, 1.8.0-update181 of Oracle JDK, 11.0.0 of Oracle JDK, 1.6.0-update201 of Oracle JRE, 1.7.0-update191 of Oracle JRE, 1.8.0-update181 of Oracle JRE, and 11.0.0 of Oracle JRE are affected by CVE-2018-14048.
What is the issue in libpng 1.6.34 that CVE-2018-14048 refers to?
CVE-2018-14048 refers to a SEGV (Segmentation Fault) issue in the function png_free_data in png.c in libpng 1.6.34.
How can I fix CVE-2018-14048 in libpng?
To fix CVE-2018-14048 in libpng, you should update to a version that contains the necessary security patches.