CVE-2018-14048: Libpng

Medium severity, CVSS 6.5. EPSS: 3.3% chance of exploitation in the next 30 days.

An issue has been found in libpng 1.6.34. It is a SEGV in the function png_free_data in png.c, related to the recommended error handling for png_read_image.

Affected products

  • Libpng Libpng: version 1.6.34 only
  • Oracle JDK: version 1.6.0 only; version 1.7.0 only; version 1.8.0 only; version 11.0.0 only
  • Oracle JRE: version 1.6.0 only; version 1.7.0 only; version 1.8.0 only; version 11.0.0 only

Published 2018-07-13. Last modified 2026-06-17.