CVE-2020-21428
published 2023-08-22CVE-2020-21428: Buffer Overflow vulnerability in function LoadRGB in PluginDDS.cpp in FreeImage 3.18.0 allows remote attackers to run arbitrary code and cause other impacts…
PriorityP335high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
0.41%
32.8th percentile
Buffer Overflow vulnerability in function LoadRGB in PluginDDS.cpp in FreeImage 3.18.0 allows remote attackers to run arbitrary code and cause other impacts via crafted image file.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | freeimage | < freeimage 3.18.0+ds2-9+deb12u1 (bookworm) | freeimage 3.18.0+ds2-9+deb12u1 (bookworm) |
| freeimage_project | freeimage | — | — |
| freeimage_project | freeimage | >= 0 < 3.18.0+ds2-6+deb11u1 | 3.18.0+ds2-6+deb11u1 |
| freeimage_project | freeimage | >= 0 < 3.18.0+ds2-9+deb12u1 | 3.18.0+ds2-9+deb12u1 |
| freeimage_project | freeimage | >= 0 < 3.18.0+ds2-10 | 3.18.0+ds2-10 |
| freeimage_project | freeimage | >= 0 < 3.18.0+ds2-10 | 3.18.0+ds2-10 |
| freeimage_project | freeimage | >= 0 < 3.18.0+ds2-1ubuntu3.1 | 3.18.0+ds2-1ubuntu3.1 |
| freeimage_project | freeimage | >= 0 < 3.18.0+ds2-6ubuntu5.1 | 3.18.0+ds2-6ubuntu5.1 |
| freeimage_project | freeimage | >= 0 < 3.15.4-3ubuntu0.1+esm3 | 3.15.4-3ubuntu0.1+esm3 |
| freeimage_project | freeimage | >= 0 < 3.17.0+ds1-2ubuntu0.1+esm1 | 3.17.0+ds1-2ubuntu0.1+esm1 |
| freeimage_project | freeimage | >= 0 < 3.17.0+ds1-5+deb9u1ubuntu0.1~esm1 | 3.17.0+ds1-5+deb9u1ubuntu0.1~esm1 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
freeimage vulnerabilities
osv·2024-01-16·CVSS 7.5
CVE-2019-12211 [HIGH] freeimage vulnerabilities
freeimage vulnerabilities
It was discovered that FreeImage incorrectly handled certain memory
operations. If a user were tricked into opening a crafted TIFF file, a
remote attacker could use this issue to cause a heap buffer overflow,
resulting in a denial of service attack. This issue only affected Ubuntu
16.04 LTS and Ubuntu 20.04 LTS. (CVE-2019-12211)
It was discovered that FreeImage incorrectly processed images under
certain circumstances. If a user were tricked into opening a crafted TIFF
file, a remote attacker could possibly use this issue to cause a stack
exhaustion condition, resulting in a denial of service attack. This issue
only affected Ubuntu 16.04 LTS and Ubuntu 20.04 LTS. (CVE-2019-12213)
It was discovered that FreeImage incorrectly processed certain images.
If a user or
OSV
CVE-2020-21428: Buffer Overflow vulnerability in function LoadRGB in PluginDDS
osv·2023-08-22·CVSS 7.8
CVE-2020-21428 [HIGH] CVE-2020-21428: Buffer Overflow vulnerability in function LoadRGB in PluginDDS
Buffer Overflow vulnerability in function LoadRGB in PluginDDS.cpp in FreeImage 3.18.0 allows remote attackers to run arbitrary code and cause other impacts via crafted image file.
GHSA
GHSA-5qcr-q6p5-3jp9: Buffer Overflow vulnerability in function LoadRGB in PluginDDS
ghsa_unreviewed·2023-08-22
CVE-2020-21428 [HIGH] CWE-120 GHSA-5qcr-q6p5-3jp9: Buffer Overflow vulnerability in function LoadRGB in PluginDDS
Buffer Overflow vulnerability in function LoadRGB in PluginDDS.cpp in FreeImage 3.18.0 allows remote attackers to run arbitrary code and cause other impacts via crafted image file.
Ubuntu
FreeImage vulnerabilities
vendor_ubuntu·2024-01-16·CVSS 7.5
CVE-2020-21427 [HIGH] FreeImage vulnerabilities
Title: FreeImage vulnerabilities
Summary: Several security issues were fixed in FreeImage.
It was discovered that FreeImage incorrectly handled certain memory
operations. If a user were tricked into opening a crafted TIFF file, a
remote attacker could use this issue to cause a heap buffer overflow,
resulting in a denial of service attack. This issue only affected Ubuntu
16.04 LTS and Ubuntu 20.04 LTS. (CVE-2019-12211)
It was discovered that FreeImage incorrectly processed images under
certain circumstances. If a user were tricked into opening a crafted TIFF
file, a remote attacker could possibly use this issue to cause a stack
exhaustion condition, resulting in a denial of service attack. This issue
only affected Ubuntu 16.04 LTS and Ubuntu 20.04 LTS. (CVE-2019-12213)
It was discovered
Debian
CVE-2020-21428: freeimage - Buffer Overflow vulnerability in function LoadRGB in PluginDDS.cpp in FreeImage ...
vendor_debian·2020·CVSS 7.8
CVE-2020-21428 [HIGH] CVE-2020-21428: freeimage - Buffer Overflow vulnerability in function LoadRGB in PluginDDS.cpp in FreeImage ...
Buffer Overflow vulnerability in function LoadRGB in PluginDDS.cpp in FreeImage 3.18.0 allows remote attackers to run arbitrary code and cause other impacts via crafted image file.
Scope: local
bookworm: resolved (fixed in 3.18.0+ds2-9+deb12u1)
bullseye: resolved (fixed in 3.18.0+ds2-6+deb11u1)
forky: resolved (fixed in 3.18.0+ds2-10)
sid: resolved (fixed in 3.18.0+ds2-10)
trixie: resolved (fixed in 3.18.0+ds2-10)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://lists.debian.org/debian-lts-announce/2023/11/msg00020.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RUEK2JOVJBQZVNQIIZZO3JFMTVB4R5KS/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UGOMCRAANNCQYJYPPMGRQWKRZGIP6NME/https://sourceforge.net/p/freeimage/bugs/299/https://www.debian.org/security/2023/dsa-5579https://lists.debian.org/debian-lts-announce/2023/11/msg00020.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RUEK2JOVJBQZVNQIIZZO3JFMTVB4R5KS/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UGOMCRAANNCQYJYPPMGRQWKRZGIP6NME/https://sourceforge.net/p/freeimage/bugs/299/https://www.debian.org/security/2023/dsa-5579
2023-08-22
Published