CVE-2018-14550: Buffer Overflow
Published Jul 10, 2019
·Updated
An issue has been found in third-party PNM decoding associated with libpng 1.6.35. It is a stack-based buffer overflow in the function gettoken in pnm2png.c in pnm2png.
Affected Software
5 affected components
libpng LIBPNG=1.6.35
Oracle Hyperion Infrastructure Technology=11.1.2.6.0
Oracle MySQL Workbench<=8.0.23
NetApp Active Iq Unified Manager Vmware Vsphere
NetApp OnCommand API Services
Remediation
Patch Available
Patch Available
Patch Available
Event History
Jul 10, 2019
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is CVE-2018-14550?
CVE-2018-14550 is a vulnerability found in third-party PNM decoding associated with libpng 1.6.35.
2
What is the severity of CVE-2018-14550?
CVE-2018-14550 has a severity value of 8.8, which is considered high.
3
Which software is affected by CVE-2018-14550?
The software affected by CVE-2018-14550 includes Libpng, Oracle Hyperion Infrastructure Technology, Oracle Mysql Workbench, Apple iPadOS, and NetApp OnCommand API Services.
4
How can I fix CVE-2018-14550?
To fix CVE-2018-14550, you should update to a patched version of the affected software.
5
Where can I find more information about CVE-2018-14550?
You can find more information about CVE-2018-14550 on the following references: [link 1], [link 2], [link 3].