First published: Fri Jul 13 2018(Updated: )
An issue has been found in libpng 1.6.34. It is a SEGV in the function png_free_data in png.c, related to the recommended error handling for png_read_image.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Libpng Libpng | =1.6.34 | |
Oracle JDK | =1.6.0-update201 | |
Oracle JDK | =1.7.0-update191 | |
Oracle JDK | =1.8.0-update181 | |
Oracle JDK | =11.0.0 | |
Oracle JRE | =1.6.0-update201 | |
Oracle JRE | =1.7.0-update191 | |
Oracle JRE | =1.8.0-update181 | |
Oracle JRE | =11.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue in libpng is CVE-2018-14048.
The severity of CVE-2018-14048 is medium, with a severity value of 6.5.
Versions 1.6.34 of libpng, 1.6.0-update201 of Oracle JDK, 1.7.0-update191 of Oracle JDK, 1.8.0-update181 of Oracle JDK, 11.0.0 of Oracle JDK, 1.6.0-update201 of Oracle JRE, 1.7.0-update191 of Oracle JRE, 1.8.0-update181 of Oracle JRE, and 11.0.0 of Oracle JRE are affected by CVE-2018-14048.
CVE-2018-14048 refers to a SEGV (Segmentation Fault) issue in the function png_free_data in png.c in libpng 1.6.34.
To fix CVE-2018-14048 in libpng, you should update to a version that contains the necessary security patches.