cbcvebase.
CVE-2020-21427
published 2023-08-22

CVE-2020-21427: Buffer Overflow vulnerability in function LoadPixelDataRLE8 in PluginBMP.cpp in FreeImage 3.18.0 allows remote attackers to run arbitrary code and cause other…

high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
Buffer Overflow vulnerability in function LoadPixelDataRLE8 in PluginBMP.cpp in FreeImage 3.18.0 allows remote attackers to run arbitrary code and cause other impacts via crafted image file.

Affected

11 ranges
VendorProductVersion rangeFixed in
debianfreeimage< freeimage 3.18.0+ds2-9+deb12u1 (bookworm)freeimage 3.18.0+ds2-9+deb12u1 (bookworm)
freeimage_projectfreeimage
freeimage_projectfreeimage>= 0 < 3.18.0+ds2-6+deb11u13.18.0+ds2-6+deb11u1
freeimage_projectfreeimage>= 0 < 3.18.0+ds2-9+deb12u13.18.0+ds2-9+deb12u1
freeimage_projectfreeimage>= 0 < 3.18.0+ds2-103.18.0+ds2-10
freeimage_projectfreeimage>= 0 < 3.18.0+ds2-103.18.0+ds2-10
freeimage_projectfreeimage>= 0 < 3.18.0+ds2-1ubuntu3.13.18.0+ds2-1ubuntu3.1
freeimage_projectfreeimage>= 0 < 3.18.0+ds2-6ubuntu5.13.18.0+ds2-6ubuntu5.1
freeimage_projectfreeimage>= 0 < 3.15.4-3ubuntu0.1+esm33.15.4-3ubuntu0.1+esm3
freeimage_projectfreeimage>= 0 < 3.17.0+ds1-2ubuntu0.1+esm13.17.0+ds1-2ubuntu0.1+esm1
freeimage_projectfreeimage>= 0 < 3.17.0+ds1-5+deb9u1ubuntu0.1~esm13.17.0+ds1-5+deb9u1ubuntu0.1~esm1

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv7.8HIGH