CVE-2018-14048
published 2018-07-13CVE-2018-14048: An issue has been found in libpng 1.6.34. It is a SEGV in the function png_free_data in png.c, related to the recommended error handling for png_read_image.
PriorityP427medium6.5CVSS 3.1
AVNACLPRNUIRSUCNINAH
EPSS
3.01%
85.9th percentile
An issue has been found in libpng 1.6.34. It is a SEGV in the function png_free_data in png.c, related to the recommended error handling for png_read_image.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libpng1.6 | < libpng1.6 1.6.37-1 (bookworm) | libpng1.6 1.6.37-1 (bookworm) |
| libpng | libpng | — | — |
| libpng | libpng | >= 0 < 1.2.54-1ubuntu1.1+esm1 | 1.2.54-1ubuntu1.1+esm1 |
| oracle | jdk | — | — |
| oracle | jdk | — | — |
| oracle | jdk | — | — |
| oracle | jdk | — | — |
| oracle | jre | — | — |
| oracle | jre | — | — |
| oracle | jre | — | — |
| oracle | jre | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv9.8CRITICAL
vendor_ubuntu9.8CRITICAL
vendor_debian6.5LOW
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
libpng vulnerabilities
vendor_ubuntu·2022-05-24·CVSS 9.8
CVE-2018-14048 [CRITICAL] libpng vulnerabilities
Title: libpng vulnerabilities
Summary: Several security issues were fixed in libpng.
USN-5432-1 fixed vulnerabilities in libpng.
This update provides the corresponding updates for libpng1.6.
Original advisory details:
It was discovered that libpng incorrectly handled memory when parsing
certain PNG files. If a user or automated system were tricked into opening
a specially crafted PNG file, an attacker could use this issue to cause
libpng to crash, resulting in a denial of service, or possibly execute
arbitrary code. (CVE-2017-12652)
Zhengxiong Luo discovered that libpng incorrectly handled memory when parsing
certain PNG files. If a user or automated system were tricked into opening
a specially crafted PNG file, an attacker could use this issue to cause
libpng to crash, resulting in a
Ubuntu
libpng vulnerabilities
vendor_ubuntu·2022-05-23·CVSS 9.8
CVE-2017-12652 [CRITICAL] libpng vulnerabilities
Title: libpng vulnerabilities
Summary: Several security issues were fixed in libpng.
It was discovered that libpng incorrectly handled memory when parsing
certain PNG files. If a user or automated system were tricked into opening
a specially crafted PNG file, an attacker could use this issue to cause
libpng to crash, resulting in a denial of service, or possible execute
arbitrary code. (CVE-2017-12652)
Zhengxiong Luo discovered that libpng incorrectly handled memory when parsing
certain PNG files. If a user or automated system were tricked into opening
a specially crafted PNG file, an attacker could use this issue to cause
libpng to crash, resulting in a denial of service, or possible execute
arbitrary code. (CVE-2018-14048)
Instructions: In general, a standard system update will make
Red Hat
libpng: Segmentation fault in png.c:png_free_data function causing denial of service
vendor_redhat·2018-07-12·CVSS 6.5
CVE-2018-14048 [MEDIUM] CWE-125 libpng: Segmentation fault in png.c:png_free_data function causing denial of service
libpng: Segmentation fault in png.c:png_free_data function causing denial of service
An issue has been found in libpng 1.6.34. It is a SEGV in the function png_free_data in png.c, related to the recommended error handling for png_read_image.
Statement: This issue did not affect the versions of libpng as shipped with Red Hat Enterprise Linux 5, 6 and 7 as they did not include the vulnerable code.
Package: libpng (Red Hat Enterprise Linux 5) - Not affected
Package: libpng (Red Hat Enterprise Linux 6) - Not affected
Package: libpng (Red Hat Enterprise Linux 7) - Not affected
Package: libpng12 (Red Hat Enterprise Linux 7) - Not affected
Package: libpng (Red Hat Enterprise Linux 8) - Not affected
Package: libpng12 (Red Hat Enterprise Linux 8) - Not affected
Package: libpng (Red Hat Ent
Debian
CVE-2018-14048: libpng1.6 - An issue has been found in libpng 1.6.34. It is a SEGV in the function png_free_...
vendor_debian·2018·CVSS 6.5
CVE-2018-14048 [MEDIUM] CVE-2018-14048: libpng1.6 - An issue has been found in libpng 1.6.34. It is a SEGV in the function png_free_...
An issue has been found in libpng 1.6.34. It is a SEGV in the function png_free_data in png.c, related to the recommended error handling for png_read_image.
Scope: local
bookworm: resolved (fixed in 1.6.37-1)
bullseye: resolved (fixed in 1.6.37-1)
forky: resolved (fixed in 1.6.37-1)
sid: resolved (fixed in 1.6.37-1)
trixie: resolved (fixed in 1.6.37-1)
OSV
libpng1.6 vulnerabilities
osv·2022-05-24·CVSS 9.8
CVE-2017-12652 [CRITICAL] libpng1.6 vulnerabilities
libpng1.6 vulnerabilities
USN-5432-1 fixed vulnerabilities in libpng.
This update provides the corresponding updates for libpng1.6.
Original advisory details:
It was discovered that libpng incorrectly handled memory when parsing
certain PNG files. If a user or automated system were tricked into opening
a specially crafted PNG file, an attacker could use this issue to cause
libpng to crash, resulting in a denial of service, or possibly execute
arbitrary code. (CVE-2017-12652)
Zhengxiong Luo discovered that libpng incorrectly handled memory when parsing
certain PNG files. If a user or automated system were tricked into opening
a specially crafted PNG file, an attacker could use this issue to cause
libpng to crash, resulting in a denial of service, or possibly execute
arbitrary code. (CVE
OSV
libpng vulnerabilities
osv·2022-05-23·CVSS 9.8
CVE-2017-12652 [CRITICAL] libpng vulnerabilities
libpng vulnerabilities
It was discovered that libpng incorrectly handled memory when parsing
certain PNG files. If a user or automated system were tricked into opening
a specially crafted PNG file, an attacker could use this issue to cause
libpng to crash, resulting in a denial of service, or possible execute
arbitrary code. (CVE-2017-12652)
Zhengxiong Luo discovered that libpng incorrectly handled memory when parsing
certain PNG files. If a user or automated system were tricked into opening
a specially crafted PNG file, an attacker could use this issue to cause
libpng to crash, resulting in a denial of service, or possible execute
arbitrary code. (CVE-2018-14048)
GHSA
GHSA-64xj-5wfx-5pjg: An issue has been found in libpng 1
ghsa_unreviewed·2022-05-13
CVE-2018-14048 [MEDIUM] GHSA-64xj-5wfx-5pjg: An issue has been found in libpng 1
An issue has been found in libpng 1.6.34. It is a SEGV in the function png_free_data in png.c, related to the recommended error handling for png_read_image.
OSV
CVE-2018-14048: An issue has been found in libpng 1
osv·2018-07-13·CVSS 6.5
CVE-2018-14048 [MEDIUM] CVE-2018-14048: An issue has been found in libpng 1
An issue has been found in libpng 1.6.34. It is a SEGV in the function png_free_data in png.c, related to the recommended error handling for png_read_image.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-14048 libpng12: libpng: Segmentation fault in png.c:png_free_data function causing denial of service [fedora-all]
bugzilla·2018-07-24·CVSS 6.5
CVE-2018-14048 [MEDIUM] CVE-2018-14048 libpng12: libpng: Segmentation fault in png.c:png_free_data function causing denial of service [fedora-all]
CVE-2018-14048 libpng12: libpng: Segmentation fault in png.c:png_free_data function causing denial of service [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: t
Bugzilla
CVE-2018-14048 libpng: Segmentation fault in png.c:png_free_data function causing denial of service
bugzilla·2018-07-24·CVSS 6.5
CVE-2018-14048 [MEDIUM] CVE-2018-14048 libpng: Segmentation fault in png.c:png_free_data function causing denial of service
CVE-2018-14048 libpng: Segmentation fault in png.c:png_free_data function causing denial of service
An issue has been found in libpng 1.6.34. It is a SEGV in the function png_free_data in png.c, related to the recommended error handling for png_read_image.
References:
https://github.com/glennrp/libpng/issues/238
https://github.com/fouzhe/security/tree/master/libpng
Discussion:
Created libpng tracking bugs for this issue:
Affects: fedora-all [bug 1608074]
Created libpng10 tracking bugs for this issue:
Affects: epel-6 [bug 1608082]
Affects: fedora-all [bug 1608075]
Created libpng12 tracking bugs for this issue:
Affects: fedora-all [bug 1608076]
Created libpng15 tracking bugs for this issue:
Affects: fedora-all [bug 1608077]
Created mingw-libpng tracking bugs for this issue:
Bugzilla
CVE-2018-14048 mingw-libpng: libpng: Segmentation fault in png.c:png_free_data function causing denial of service [epel-7]
bugzilla·2018-07-24·CVSS 6.5
CVE-2018-14048 [MEDIUM] CVE-2018-14048 mingw-libpng: libpng: Segmentation fault in png.c:png_free_data function causing denial of service [epel-7]
CVE-2018-14048 mingw-libpng: libpng: Segmentation fault in png.c:png_free_data function causing denial of service [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-7.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion
Bugzilla
CVE-2018-14048 libpng10: libpng: Segmentation fault in png.c:png_free_data function causing denial of service [fedora-all]
bugzilla·2018-07-24·CVSS 6.5
CVE-2018-14048 [MEDIUM] CVE-2018-14048 libpng10: libpng: Segmentation fault in png.c:png_free_data function causing denial of service [fedora-all]
CVE-2018-14048 libpng10: libpng: Segmentation fault in png.c:png_free_data function causing denial of service [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: t
Bugzilla
CVE-2018-14048 libpng10: libpng: Segmentation fault in png.c:png_free_data function causing denial of service [epel-6]
bugzilla·2018-07-24·CVSS 6.5
CVE-2018-14048 [MEDIUM] CVE-2018-14048 libpng10: libpng: Segmentation fault in png.c:png_free_data function causing denial of service [epel-6]
CVE-2018-14048 libpng10: libpng: Segmentation fault in png.c:png_free_data function causing denial of service [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-6.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Us
Bugzilla
CVE-2018-14048 libpng: Segmentation fault in png.c:png_free_data function causing denial of service [fedora-all]
bugzilla·2018-07-24·CVSS 6.5
CVE-2018-14048 [MEDIUM] CVE-2018-14048 libpng: Segmentation fault in png.c:png_free_data function causing denial of service [fedora-all]
CVE-2018-14048 libpng: Segmentation fault in png.c:png_free_data function causing denial of service [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue
Bugzilla
CVE-2018-14048 libpng15: libpng: Segmentation fault in png.c:png_free_data function causing denial of service [fedora-all]
bugzilla·2018-07-24·CVSS 6.5
CVE-2018-14048 [MEDIUM] CVE-2018-14048 libpng15: libpng: Segmentation fault in png.c:png_free_data function causing denial of service [fedora-all]
CVE-2018-14048 libpng15: libpng: Segmentation fault in png.c:png_free_data function causing denial of service [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: t
Bugzilla
CVE-2018-14048 mingw-libpng: libpng: Segmentation fault in png.c:png_free_data function causing denial of service [fedora-all]
bugzilla·2018-07-24·CVSS 6.5
CVE-2018-14048 [MEDIUM] CVE-2018-14048 mingw-libpng: libpng: Segmentation fault in png.c:png_free_data function causing denial of service [fedora-all]
CVE-2018-14048 mingw-libpng: libpng: Segmentation fault in png.c:png_free_data function causing denial of service [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOT
arXiv
Directed Greybox Fuzzing via Large Language Model
arxiv_fulltext·2025-05-06
Directed Greybox Fuzzing via Large Language Model
Directed Greybox Fuzzing via Large Language Model
Hanxiang Xu
Huazhong University of Science and Technology
China
[email protected]
Yanjie Zhao
Huazhong University of Science and Technology
China
[email protected]
Haoyu Wang
Huazhong University of Science and Technology
China
[email protected]
## Abstract
Directed greybox fuzzing (DGF) focuses on efficiently reaching specific program locations or triggering particular behaviors, making it essential for tasks like vulnerability detection and crash reproduction. However, existing methods often suffer from path explosion and randomness in input mutation, leading to inefficiencies in exploring and exploiting target paths. In this paper, we propose , an automatic framework that leverages the large language model (LLM) to add
http://packetstormsecurity.com/files/152561/Slackware-Security-Advisory-libpng-Updates.htmlhttp://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.htmlhttps://github.com/fouzhe/security/tree/master/libpnghttps://github.com/glennrp/libpng/issues/238https://seclists.org/bugtraq/2019/Apr/30https://security.gentoo.org/glsa/201908-02http://packetstormsecurity.com/files/152561/Slackware-Security-Advisory-libpng-Updates.htmlhttp://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.htmlhttps://github.com/fouzhe/security/tree/master/libpnghttps://github.com/glennrp/libpng/issues/238https://seclists.org/bugtraq/2019/Apr/30https://security.gentoo.org/glsa/201908-02
2018-07-13
Published