High severity8.8NVD Advisory· Published Jul 10, 2019· Updated Jun 17, 2026
CVE-2018-14550
CVE-2018-14550
Description
An issue has been found in third-party PNM decoding associated with libpng 1.6.35. It is a stack-based buffer overflow in the function get_token in pnm2png.c in pnm2png.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
libpngNuGet | < 1.6.37 | 1.6.37 |
Affected products
7- cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:*
- cpe:2.3:a:netapp:oncommand_api_services:-:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:hyperion_infrastructure_technology:11.1.2.6.0:*:*:*:*:*:*:*
- libpng/libpngdescription
Patches
Vulnerability mechanics
References
10- www.oracle.com/security-alerts/cpuApr2021.htmlnvdPatchThird Party AdvisoryWEB
- www.oracle.com/security-alerts/cpuoct2021.htmlnvdPatchThird Party AdvisoryWEB
- github.com/fouzhe/security/tree/master/libpngnvdExploitPatchThird Party AdvisoryWEB
- github.com/glennrp/libpng/issues/246nvdExploitPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-qwwr-qc2p-6283ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2018-14550ghsaADVISORY
- security.gentoo.org/glsa/201908-02nvdThird Party AdvisoryWEB
- security.netapp.com/advisory/ntap-20221028-0001/nvdThird Party Advisory
- security.netapp.com/advisory/ntap-20221028-0001ghsaWEB
- snyk.io/vuln/SNYK-UPSTREAM-LIBPNG-1043612ghsaWEB
News mentions
0No linked articles in our index yet.