cbcvebase.
CVE-2020-21428
published 2023-08-22

CVE-2020-21428: Buffer Overflow vulnerability in function LoadRGB in PluginDDS.cpp in FreeImage 3.18.0 allows remote attackers to run arbitrary code and cause other impacts…

PriorityP335high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
0.41%
32.8th percentile
Buffer Overflow vulnerability in function LoadRGB in PluginDDS.cpp in FreeImage 3.18.0 allows remote attackers to run arbitrary code and cause other impacts via crafted image file.

Affected

11 ranges
VendorProductVersion rangeFixed in
debianfreeimage< freeimage 3.18.0+ds2-9+deb12u1 (bookworm)freeimage 3.18.0+ds2-9+deb12u1 (bookworm)
freeimage_projectfreeimage
freeimage_projectfreeimage>= 0 < 3.18.0+ds2-6+deb11u13.18.0+ds2-6+deb11u1
freeimage_projectfreeimage>= 0 < 3.18.0+ds2-9+deb12u13.18.0+ds2-9+deb12u1
freeimage_projectfreeimage>= 0 < 3.18.0+ds2-103.18.0+ds2-10
freeimage_projectfreeimage>= 0 < 3.18.0+ds2-103.18.0+ds2-10
freeimage_projectfreeimage>= 0 < 3.18.0+ds2-1ubuntu3.13.18.0+ds2-1ubuntu3.1
freeimage_projectfreeimage>= 0 < 3.18.0+ds2-6ubuntu5.13.18.0+ds2-6ubuntu5.1
freeimage_projectfreeimage>= 0 < 3.15.4-3ubuntu0.1+esm33.15.4-3ubuntu0.1+esm3
freeimage_projectfreeimage>= 0 < 3.17.0+ds1-2ubuntu0.1+esm13.17.0+ds1-2ubuntu0.1+esm1
freeimage_projectfreeimage>= 0 < 3.17.0+ds1-5+deb9u1ubuntu0.1~esm13.17.0+ds1-5+deb9u1ubuntu0.1~esm1

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.