CVE-2018-14550: Libpng

High severity, CVSS 8.8. EPSS: 3.5% chance of exploitation in the next 30 days.

An issue has been found in third-party PNM decoding associated with libpng 1.6.35. It is a stack-based buffer overflow in the function get_token in pnm2png.c in pnm2png.

Affected products

  • Libpng Libpng: version 1.6.35 only
  • Netapp Active Iq Unified Manager: affected versions not specified
  • Netapp Oncommand API Services: affected versions not specified
  • Oracle Hyperion Infrastructure Technology: version 11.1.2.6.0 only
  • Oracle MySQL Workbench: up to and including 8.0.23

Published 2019-07-10. Last modified 2026-06-17.