CVE-2018-14876: Medium severity flif vulnerability
An issue was discovered in imagesavepng in image/image-png.cpp in Free Lossless Image Format (FLIF) 0.3. Attackers can trigger a longjmp that leads to an uninitialized stack frame after a libpng error concerning the IHDR image width.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-14876?
The severity of CVE-2018-14876 is medium with a CVSS score of 5.5.
What is the affected software for CVE-2018-14876?
The affected software for CVE-2018-14876 is Flif Flif version 0.3.
How can attackers exploit CVE-2018-14876?
Attackers can trigger a longjmp that leads to an uninitialized stack frame after a libpng error concerning the IHDR image width in CVE-2018-14876.
Is there a fix available for CVE-2018-14876?
A fix for CVE-2018-14876 may be available in a future update or patch. It is recommended to follow the recommendations of the software vendor.
Where can I find more information about CVE-2018-14876?
You can find more information about CVE-2018-14876 on the following link: https://github.com/FLIF-hub/FLIF/issues/520