VulnerabilityModified
CVE-2018-14047
An issue has been found in PNGwriter 0.7.0.
MEDIUM 5.5EPSS 0.95%
Does this matter?
Lower severity and a low EPSS score (0.95%). Track it; it rarely justifies an emergency change on its own.
Description
An issue has been found in PNGwriter 0.7.0. It is a SEGV in pngwriter::readfromfile in pngwriter.cc. NOTE: there is a "Warning: PNGwriter was never designed for reading untrusted files with it. Do NOT use this in sensitive environments, especially DO NOT read PNGs from unknown sources with it!" statement in the master/README.md file
- CVSS 3.0
- 5.5 MEDIUMCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
- EPSS
- 0.95% probability · 59th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- pngwriter project/pngwriter
- Source
- cve@mitre.org
References
- https://github.com/fouzhe/security/tree/master/pngwriterExploit, Third Party Advisory
- https://github.com/pngwriter/pngwriter/issues/129Exploit, Third Party Advisory
- https://github.com/fouzhe/security/tree/master/pngwriterExploit, Third Party Advisory
- https://github.com/pngwriter/pngwriter/issues/129Exploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.