CVE-2020-22524
published 2023-08-22CVE-2020-22524: Buffer Overflow vulnerability in FreeImage_Load function in FreeImage Library 3.19.0(r1828) allows attackers to cuase a denial of service via crafted PFM file.
PriorityP426medium6.5CVSS 3.1
AVNACLPRNUIRSUCNINAH
EPSS
0.90%
55.5th percentile
Buffer Overflow vulnerability in FreeImage_Load function in FreeImage Library 3.19.0(r1828) allows attackers to cuase a denial of service via crafted PFM file.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | freeimage | < freeimage 3.18.0+ds2-9+deb12u1 (bookworm) | freeimage 3.18.0+ds2-9+deb12u1 (bookworm) |
| freeimage_project | freeimage | — | — |
| freeimage_project | freeimage | >= 0 < 3.18.0+ds2-6+deb11u1 | 3.18.0+ds2-6+deb11u1 |
| freeimage_project | freeimage | >= 0 < 3.18.0+ds2-9+deb12u1 | 3.18.0+ds2-9+deb12u1 |
| freeimage_project | freeimage | >= 0 < 3.18.0+ds2-10 | 3.18.0+ds2-10 |
| freeimage_project | freeimage | >= 0 < 3.18.0+ds2-10 | 3.18.0+ds2-10 |
| freeimage_project | freeimage | >= 0 < 3.18.0+ds2-1ubuntu3.1 | 3.18.0+ds2-1ubuntu3.1 |
| freeimage_project | freeimage | >= 0 < 3.18.0+ds2-6ubuntu5.1 | 3.18.0+ds2-6ubuntu5.1 |
| freeimage_project | freeimage | >= 0 < 3.15.4-3ubuntu0.1+esm3 | 3.15.4-3ubuntu0.1+esm3 |
| freeimage_project | freeimage | >= 0 < 3.17.0+ds1-2ubuntu0.1+esm1 | 3.17.0+ds1-2ubuntu0.1+esm1 |
| freeimage_project | freeimage | >= 0 < 3.17.0+ds1-5+deb9u1ubuntu0.1~esm1 | 3.17.0+ds1-5+deb9u1ubuntu0.1~esm1 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_ubuntu7.5HIGH
vendor_debian6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
freeimage vulnerabilities
osv·2024-01-16·CVSS 7.5
CVE-2019-12211 [HIGH] freeimage vulnerabilities
freeimage vulnerabilities
It was discovered that FreeImage incorrectly handled certain memory
operations. If a user were tricked into opening a crafted TIFF file, a
remote attacker could use this issue to cause a heap buffer overflow,
resulting in a denial of service attack. This issue only affected Ubuntu
16.04 LTS and Ubuntu 20.04 LTS. (CVE-2019-12211)
It was discovered that FreeImage incorrectly processed images under
certain circumstances. If a user were tricked into opening a crafted TIFF
file, a remote attacker could possibly use this issue to cause a stack
exhaustion condition, resulting in a denial of service attack. This issue
only affected Ubuntu 16.04 LTS and Ubuntu 20.04 LTS. (CVE-2019-12213)
It was discovered that FreeImage incorrectly processed certain images.
If a user or
GHSA
GHSA-qrgg-mgwx-hq8f: Buffer Overflow vulnerability in FreeImage_Load function in FreeImage Library 3
ghsa_unreviewed·2023-08-22
CVE-2020-22524 [MEDIUM] CWE-120 GHSA-qrgg-mgwx-hq8f: Buffer Overflow vulnerability in FreeImage_Load function in FreeImage Library 3
Buffer Overflow vulnerability in FreeImage_Load function in FreeImage Library 3.19.0(r1828) allows attackers to cuase a denial of service via crafted PFM file.
OSV
CVE-2020-22524: Buffer Overflow vulnerability in FreeImage_Load function in FreeImage Library 3
osv·2023-08-22·CVSS 6.5
CVE-2020-22524 [MEDIUM] CVE-2020-22524: Buffer Overflow vulnerability in FreeImage_Load function in FreeImage Library 3
Buffer Overflow vulnerability in FreeImage_Load function in FreeImage Library 3.19.0(r1828) allows attackers to cuase a denial of service via crafted PFM file.
Ubuntu
FreeImage vulnerabilities
vendor_ubuntu·2024-01-16·CVSS 7.5
CVE-2020-21427 [HIGH] FreeImage vulnerabilities
Title: FreeImage vulnerabilities
Summary: Several security issues were fixed in FreeImage.
It was discovered that FreeImage incorrectly handled certain memory
operations. If a user were tricked into opening a crafted TIFF file, a
remote attacker could use this issue to cause a heap buffer overflow,
resulting in a denial of service attack. This issue only affected Ubuntu
16.04 LTS and Ubuntu 20.04 LTS. (CVE-2019-12211)
It was discovered that FreeImage incorrectly processed images under
certain circumstances. If a user were tricked into opening a crafted TIFF
file, a remote attacker could possibly use this issue to cause a stack
exhaustion condition, resulting in a denial of service attack. This issue
only affected Ubuntu 16.04 LTS and Ubuntu 20.04 LTS. (CVE-2019-12213)
It was discovered
Debian
CVE-2020-22524: freeimage - Buffer Overflow vulnerability in FreeImage_Load function in FreeImage Library 3....
vendor_debian·2020·CVSS 6.5
CVE-2020-22524 [MEDIUM] CVE-2020-22524: freeimage - Buffer Overflow vulnerability in FreeImage_Load function in FreeImage Library 3....
Buffer Overflow vulnerability in FreeImage_Load function in FreeImage Library 3.19.0(r1828) allows attackers to cuase a denial of service via crafted PFM file.
Scope: local
bookworm: resolved (fixed in 3.18.0+ds2-9+deb12u1)
bullseye: resolved (fixed in 3.18.0+ds2-6+deb11u1)
forky: resolved (fixed in 3.18.0+ds2-10)
sid: resolved (fixed in 3.18.0+ds2-10)
trixie: resolved (fixed in 3.18.0+ds2-10)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://lists.debian.org/debian-lts-announce/2023/11/msg00020.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RUEK2JOVJBQZVNQIIZZO3JFMTVB4R5KS/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UGOMCRAANNCQYJYPPMGRQWKRZGIP6NME/https://sourceforge.net/p/freeimage/bugs/319/https://www.debian.org/security/2023/dsa-5579https://lists.debian.org/debian-lts-announce/2023/11/msg00020.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RUEK2JOVJBQZVNQIIZZO3JFMTVB4R5KS/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UGOMCRAANNCQYJYPPMGRQWKRZGIP6NME/https://sourceforge.net/p/freeimage/bugs/319/https://www.debian.org/security/2023/dsa-5579
2023-08-22
Published