CVE-2019-12213
published 2019-05-20CVE-2019-12213: When FreeImage 3.18.0 reads a special TIFF file, the TIFFReadDirectory function in PluginTIFF.cpp always returns 1, leading to stack exhaustion.
medium6.5CVSS 3.1
AVNACLPRNUIRSUCNINAH
When FreeImage 3.18.0 reads a special TIFF file, the TIFFReadDirectory function in PluginTIFF.cpp always returns 1, leading to stack exhaustion.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | freeimage | < freeimage 3.18.0+ds2-3 (bookworm) | freeimage 3.18.0+ds2-3 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| freeimage_project | freeimage | — | — |
| freeimage_project | freeimage | >= 0 < 3.18.0+ds2-3 | 3.18.0+ds2-3 |
| freeimage_project | freeimage | >= 0 < 3.18.0+ds2-3 | 3.18.0+ds2-3 |
| freeimage_project | freeimage | >= 0 < 3.18.0+ds2-3 | 3.18.0+ds2-3 |
| freeimage_project | freeimage | >= 0 < 3.18.0+ds2-3 | 3.18.0+ds2-3 |
| freeimage_project | freeimage | >= 0 < 3.17.0+ds1-5+deb9u1build0.18.04.1 | 3.17.0+ds1-5+deb9u1build0.18.04.1 |
| freeimage_project | freeimage | >= 0 < 3.18.0+ds2-1ubuntu3.1 | 3.18.0+ds2-1ubuntu3.1 |
| freeimage_project | freeimage | >= 0 < 3.18.0+ds2-6ubuntu5.1 | 3.18.0+ds2-6ubuntu5.1 |
| freeimage_project | freeimage | >= 0 < 3.15.4-3ubuntu0.1+esm3 | 3.15.4-3ubuntu0.1+esm3 |
| freeimage_project | freeimage | >= 0 < 3.17.0+ds1-2ubuntu0.1+esm1 | 3.17.0+ds1-2ubuntu0.1+esm1 |
| freeimage_project | freeimage | >= 0 < 3.17.0+ds1-5+deb9u1ubuntu0.1~esm1 | 3.17.0+ds1-5+deb9u1ubuntu0.1~esm1 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
osv7.5HIGH