CVE-2020-21427
published 2023-08-22CVE-2020-21427: Buffer Overflow vulnerability in function LoadPixelDataRLE8 in PluginBMP.cpp in FreeImage 3.18.0 allows remote attackers to run arbitrary code and cause other…
PriorityP335high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
0.54%
41.7th percentile
Buffer Overflow vulnerability in function LoadPixelDataRLE8 in PluginBMP.cpp in FreeImage 3.18.0 allows remote attackers to run arbitrary code and cause other impacts via crafted image file.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | freeimage | < freeimage 3.18.0+ds2-9+deb12u1 (bookworm) | freeimage 3.18.0+ds2-9+deb12u1 (bookworm) |
| freeimage_project | freeimage | — | — |
| freeimage_project | freeimage | >= 0 < 3.18.0+ds2-6+deb11u1 | 3.18.0+ds2-6+deb11u1 |
| freeimage_project | freeimage | >= 0 < 3.18.0+ds2-9+deb12u1 | 3.18.0+ds2-9+deb12u1 |
| freeimage_project | freeimage | >= 0 < 3.18.0+ds2-10 | 3.18.0+ds2-10 |
| freeimage_project | freeimage | >= 0 < 3.18.0+ds2-10 | 3.18.0+ds2-10 |
| freeimage_project | freeimage | >= 0 < 3.18.0+ds2-1ubuntu3.1 | 3.18.0+ds2-1ubuntu3.1 |
| freeimage_project | freeimage | >= 0 < 3.18.0+ds2-6ubuntu5.1 | 3.18.0+ds2-6ubuntu5.1 |
| freeimage_project | freeimage | >= 0 < 3.15.4-3ubuntu0.1+esm3 | 3.15.4-3ubuntu0.1+esm3 |
| freeimage_project | freeimage | >= 0 < 3.17.0+ds1-2ubuntu0.1+esm1 | 3.17.0+ds1-2ubuntu0.1+esm1 |
| freeimage_project | freeimage | >= 0 < 3.17.0+ds1-5+deb9u1ubuntu0.1~esm1 | 3.17.0+ds1-5+deb9u1ubuntu0.1~esm1 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
freeimage vulnerabilities
osv·2024-01-16·CVSS 7.5
CVE-2019-12211 [HIGH] freeimage vulnerabilities
freeimage vulnerabilities
It was discovered that FreeImage incorrectly handled certain memory
operations. If a user were tricked into opening a crafted TIFF file, a
remote attacker could use this issue to cause a heap buffer overflow,
resulting in a denial of service attack. This issue only affected Ubuntu
16.04 LTS and Ubuntu 20.04 LTS. (CVE-2019-12211)
It was discovered that FreeImage incorrectly processed images under
certain circumstances. If a user were tricked into opening a crafted TIFF
file, a remote attacker could possibly use this issue to cause a stack
exhaustion condition, resulting in a denial of service attack. This issue
only affected Ubuntu 16.04 LTS and Ubuntu 20.04 LTS. (CVE-2019-12213)
It was discovered that FreeImage incorrectly processed certain images.
If a user or
GHSA
GHSA-xjvv-5w4r-hfmv: Buffer Overflow vulnerability in function LoadPixelDataRLE8 in PluginBMP
ghsa_unreviewed·2023-08-22
CVE-2020-21427 [HIGH] CWE-120 GHSA-xjvv-5w4r-hfmv: Buffer Overflow vulnerability in function LoadPixelDataRLE8 in PluginBMP
Buffer Overflow vulnerability in function LoadPixelDataRLE8 in PluginBMP.cpp in FreeImage 3.18.0 allows remote attackers to run arbitrary code and cause other impacts via crafted image file.
OSV
CVE-2020-21427: Buffer Overflow vulnerability in function LoadPixelDataRLE8 in PluginBMP
osv·2023-08-22·CVSS 7.8
CVE-2020-21427 [HIGH] CVE-2020-21427: Buffer Overflow vulnerability in function LoadPixelDataRLE8 in PluginBMP
Buffer Overflow vulnerability in function LoadPixelDataRLE8 in PluginBMP.cpp in FreeImage 3.18.0 allows remote attackers to run arbitrary code and cause other impacts via crafted image file.
Ubuntu
FreeImage vulnerabilities
vendor_ubuntu·2024-01-16·CVSS 7.5
CVE-2020-21427 [HIGH] FreeImage vulnerabilities
Title: FreeImage vulnerabilities
Summary: Several security issues were fixed in FreeImage.
It was discovered that FreeImage incorrectly handled certain memory
operations. If a user were tricked into opening a crafted TIFF file, a
remote attacker could use this issue to cause a heap buffer overflow,
resulting in a denial of service attack. This issue only affected Ubuntu
16.04 LTS and Ubuntu 20.04 LTS. (CVE-2019-12211)
It was discovered that FreeImage incorrectly processed images under
certain circumstances. If a user were tricked into opening a crafted TIFF
file, a remote attacker could possibly use this issue to cause a stack
exhaustion condition, resulting in a denial of service attack. This issue
only affected Ubuntu 16.04 LTS and Ubuntu 20.04 LTS. (CVE-2019-12213)
It was discovered
Debian
CVE-2020-21427: freeimage - Buffer Overflow vulnerability in function LoadPixelDataRLE8 in PluginBMP.cpp in ...
vendor_debian·2020·CVSS 7.8
CVE-2020-21427 [HIGH] CVE-2020-21427: freeimage - Buffer Overflow vulnerability in function LoadPixelDataRLE8 in PluginBMP.cpp in ...
Buffer Overflow vulnerability in function LoadPixelDataRLE8 in PluginBMP.cpp in FreeImage 3.18.0 allows remote attackers to run arbitrary code and cause other impacts via crafted image file.
Scope: local
bookworm: resolved (fixed in 3.18.0+ds2-9+deb12u1)
bullseye: resolved (fixed in 3.18.0+ds2-6+deb11u1)
forky: resolved (fixed in 3.18.0+ds2-10)
sid: resolved (fixed in 3.18.0+ds2-10)
trixie: resolved (fixed in 3.18.0+ds2-10)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://lists.debian.org/debian-lts-announce/2023/11/msg00020.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RUEK2JOVJBQZVNQIIZZO3JFMTVB4R5KS/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UGOMCRAANNCQYJYPPMGRQWKRZGIP6NME/https://sourceforge.net/p/freeimage/bugs/298/https://www.debian.org/security/2023/dsa-5579https://lists.debian.org/debian-lts-announce/2023/11/msg00020.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RUEK2JOVJBQZVNQIIZZO3JFMTVB4R5KS/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UGOMCRAANNCQYJYPPMGRQWKRZGIP6NME/https://sourceforge.net/p/freeimage/bugs/298/https://www.debian.org/security/2023/dsa-5579
2023-08-22
Published