cbcvebase.
CVE-2020-22524
published 2023-08-22

CVE-2020-22524: Buffer Overflow vulnerability in FreeImage_Load function in FreeImage Library 3.19.0(r1828) allows attackers to cuase a denial of service via crafted PFM file.

medium6.5CVSS 3.1
AVNACLPRNUIRSUCNINAH
Buffer Overflow vulnerability in FreeImage_Load function in FreeImage Library 3.19.0(r1828) allows attackers to cuase a denial of service via crafted PFM file.

Affected

11 ranges
VendorProductVersion rangeFixed in
debianfreeimage< freeimage 3.18.0+ds2-9+deb12u1 (bookworm)freeimage 3.18.0+ds2-9+deb12u1 (bookworm)
freeimage_projectfreeimage
freeimage_projectfreeimage>= 0 < 3.18.0+ds2-6+deb11u13.18.0+ds2-6+deb11u1
freeimage_projectfreeimage>= 0 < 3.18.0+ds2-9+deb12u13.18.0+ds2-9+deb12u1
freeimage_projectfreeimage>= 0 < 3.18.0+ds2-103.18.0+ds2-10
freeimage_projectfreeimage>= 0 < 3.18.0+ds2-103.18.0+ds2-10
freeimage_projectfreeimage>= 0 < 3.18.0+ds2-1ubuntu3.13.18.0+ds2-1ubuntu3.1
freeimage_projectfreeimage>= 0 < 3.18.0+ds2-6ubuntu5.13.18.0+ds2-6ubuntu5.1
freeimage_projectfreeimage>= 0 < 3.15.4-3ubuntu0.1+esm33.15.4-3ubuntu0.1+esm3
freeimage_projectfreeimage>= 0 < 3.17.0+ds1-2ubuntu0.1+esm13.17.0+ds1-2ubuntu0.1+esm1
freeimage_projectfreeimage>= 0 < 3.17.0+ds1-5+deb9u1ubuntu0.1~esm13.17.0+ds1-5+deb9u1ubuntu0.1~esm1

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
osv7.5HIGH