CVE-2016-5684Out-of-bounds Write in Freeimage

CWE-787Out-of-bounds Write12 documents8 sources
Severity
7.8HIGHNVD
EPSS
0.5%
top 34.15%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 6
Latest updateMay 14

Description

An exploitable out-of-bounds write vulnerability exists in the XMP image handling functionality of the FreeImage library. A specially crafted XMP file can cause an arbitrary memory overwrite resulting in code execution. An attacker can provide a malicious image to trigger this vulnerability.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages3 packages

Debianfreeimage_project/freeimage< 3.17.0+ds1-3+3
CVEListV5freeimage/freeimage3.17.0

🔴Vulnerability Details

3
GHSA
GHSA-wf6p-hgq4-x57x: An exploitable out-of-bounds write vulnerability exists in the XMP image handling functionality of the FreeImage library2022-05-14
OSV
CVE-2016-5684: An exploitable out-of-bounds write vulnerability exists in the XMP image handling functionality of the FreeImage library2017-01-06
CVEList
CVE-2016-5684: An exploitable out-of-bounds write vulnerability exists in the XMP image handling functionality of the FreeImage library2017-01-06

📋Vendor Advisories

2
Ubuntu
FreeImage vulnerability2019-03-28
Debian
CVE-2016-5684: freeimage - An exploitable out-of-bounds write vulnerability exists in the XMP image handlin...2016

🕵️Threat Intelligence

2
Talos
Vulnerability Spotlight: FreeImage Library XMP Image Handling Code Execution Vulnerability2016-10-03
Talos
Vulnerability Spotlight: FreeImage Library XMP Image Handling Code Execution Vulnerability2016-10-03

💬Community

4
Bugzilla
CVE-2016-5684 mingw-freeimage: freeimage: XMP Image Handling Code Execution Vulnerability [fedora-all]2016-10-04
Bugzilla
CVE-2016-5684 freeimage: XMP Image Handling Code Execution Vulnerability [fedora-all]2016-10-04
Bugzilla
CVE-2016-5684 freeimage: XMP Image Handling Code Execution Vulnerability [epel-all]2016-10-04
Bugzilla
CVE-2016-5684 freeimage: XMP Image Handling Code Execution Vulnerability2016-10-04
CVE-2016-5684 — Out-of-bounds Write in Freeimage | cvebase