CVE-2018-14876: Flif

Medium severity, CVSS 5.5. EPSS: 0.9% chance of exploitation in the next 30 days.

An issue was discovered in image_save_png in image/image-png.cpp in Free Lossless Image Format (FLIF) 0.3. Attackers can trigger a longjmp that leads to an uninitialized stack frame after a libpng error concerning the IHDR image width.

Affected products

  • Flif Flif: version 0.3 only

Published 2018-08-03. Last modified 2026-06-17.