CVE-2018-14048: Libpng
Medium severity, CVSS 6.5. EPSS: 3.3% chance of exploitation in the next 30 days.
An issue has been found in libpng 1.6.34. It is a SEGV in the function png_free_data in png.c, related to the recommended error handling for png_read_image.
Affected products
- Libpng Libpng: version 1.6.34 only
- Oracle JDK: version 1.6.0 only; version 1.7.0 only; version 1.8.0 only; version 11.0.0 only
- Oracle JRE: version 1.6.0 only; version 1.7.0 only; version 1.8.0 only; version 11.0.0 only
Published 2018-07-13. Last modified 2026-06-17.