---
cve: "CVE-2018-14550"
severity: "LOW"
cvss: 3.1
epss: "3.5%"
vendor: "n/a"
kev: false
exploited: false
published: "2019-07-10 12:15:10"
tags: [cve, security, low]
source: tsecurity.de CVE-Dossier
exported: "2026-09-11T07:39:16+02:00"
---

# CVE-2018-14550

> 3.1 LOW · 🧪 PoC

## Beschreibung

An issue has been found in third-party PNM decoding associated with libpng 1.6.35. It is a stack-based buffer overflow in the function get_token in pnm2png.c in pnm2png.

## Referenzen

- <https://security.gentoo.org/glsa/201908-02>
- <https://www.oracle.com/security-alerts/cpuApr2021.html>
- <https://github.com/glennrp/libpng/issues/246>
- <https://github.com/fouzhe/security/tree/master/libpng#stack-buffer-overflow-in-png2pnm-in-function-get_token>
- <https://www.oracle.com/security-alerts/cpuoct2021.html>
- <https://security.netapp.com/advisory/ntap-20221028-0001/>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2018-14550) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
