PT-2023-11667 · Freeimage+1 · Freeimage+1

Avscx

·

Publicado

2023-08-22

·

Atualizado

2024-11-01

·

CVE-2020-24292

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions FreeImage version 3.19.0
Description A Buffer Overflow issue exists in the load function in PluginICO.cpp, allowing remote attackers to run arbitrary code via the opening of crafted ico files.
Recommendations For FreeImage version 3.19.0, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2020-24292
OESA-2024-2305

Produtos afetados

Debian
Freeimage