CVE-2020-21427
published 2023-08-22CVE-2020-21427: Buffer Overflow vulnerability in function LoadPixelDataRLE8 in PluginBMP.cpp in FreeImage 3.18.0 allows remote attackers to run arbitrary code and cause other…
high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
Buffer Overflow vulnerability in function LoadPixelDataRLE8 in PluginBMP.cpp in FreeImage 3.18.0 allows remote attackers to run arbitrary code and cause other impacts via crafted image file.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | freeimage | < freeimage 3.18.0+ds2-9+deb12u1 (bookworm) | freeimage 3.18.0+ds2-9+deb12u1 (bookworm) |
| freeimage_project | freeimage | — | — |
| freeimage_project | freeimage | >= 0 < 3.18.0+ds2-6+deb11u1 | 3.18.0+ds2-6+deb11u1 |
| freeimage_project | freeimage | >= 0 < 3.18.0+ds2-9+deb12u1 | 3.18.0+ds2-9+deb12u1 |
| freeimage_project | freeimage | >= 0 < 3.18.0+ds2-10 | 3.18.0+ds2-10 |
| freeimage_project | freeimage | >= 0 < 3.18.0+ds2-10 | 3.18.0+ds2-10 |
| freeimage_project | freeimage | >= 0 < 3.18.0+ds2-1ubuntu3.1 | 3.18.0+ds2-1ubuntu3.1 |
| freeimage_project | freeimage | >= 0 < 3.18.0+ds2-6ubuntu5.1 | 3.18.0+ds2-6ubuntu5.1 |
| freeimage_project | freeimage | >= 0 < 3.15.4-3ubuntu0.1+esm3 | 3.15.4-3ubuntu0.1+esm3 |
| freeimage_project | freeimage | >= 0 < 3.17.0+ds1-2ubuntu0.1+esm1 | 3.17.0+ds1-2ubuntu0.1+esm1 |
| freeimage_project | freeimage | >= 0 < 3.17.0+ds1-5+deb9u1ubuntu0.1~esm1 | 3.17.0+ds1-5+deb9u1ubuntu0.1~esm1 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv7.8HIGH