cbcvebase.
CVE-2020-21428
published 2023-08-22

CVE-2020-21428: Buffer Overflow vulnerability in function LoadRGB in PluginDDS.cpp in FreeImage 3.18.0 allows remote attackers to run arbitrary code and cause other impacts…

high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
Buffer Overflow vulnerability in function LoadRGB in PluginDDS.cpp in FreeImage 3.18.0 allows remote attackers to run arbitrary code and cause other impacts via crafted image file.

Affected

11 ranges
VendorProductVersion rangeFixed in
debianfreeimage< freeimage 3.18.0+ds2-9+deb12u1 (bookworm)freeimage 3.18.0+ds2-9+deb12u1 (bookworm)
freeimage_projectfreeimage
freeimage_projectfreeimage>= 0 < 3.18.0+ds2-6+deb11u13.18.0+ds2-6+deb11u1
freeimage_projectfreeimage>= 0 < 3.18.0+ds2-9+deb12u13.18.0+ds2-9+deb12u1
freeimage_projectfreeimage>= 0 < 3.18.0+ds2-103.18.0+ds2-10
freeimage_projectfreeimage>= 0 < 3.18.0+ds2-103.18.0+ds2-10
freeimage_projectfreeimage>= 0 < 3.18.0+ds2-1ubuntu3.13.18.0+ds2-1ubuntu3.1
freeimage_projectfreeimage>= 0 < 3.18.0+ds2-6ubuntu5.13.18.0+ds2-6ubuntu5.1
freeimage_projectfreeimage>= 0 < 3.15.4-3ubuntu0.1+esm33.15.4-3ubuntu0.1+esm3
freeimage_projectfreeimage>= 0 < 3.17.0+ds1-2ubuntu0.1+esm13.17.0+ds1-2ubuntu0.1+esm1
freeimage_projectfreeimage>= 0 < 3.17.0+ds1-5+deb9u1ubuntu0.1~esm13.17.0+ds1-5+deb9u1ubuntu0.1~esm1

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv7.8HIGH