PT-2019-12700 · Freeimage+1 · Freeimage+1

Taolaw

·

Published

2019-05-20

·

Updated

2020-08-24

·

CVE-2019-12212

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions FreeImage version 3.18.0
Description The issue arises when processing a specially crafted JXR file, causing the StreamCalcIFDSize function in JXRMeta.c to recursively call itself due to improper file handling, leading to stack exhaustion. This can be exploited by an attacker to achieve a remote denial of service attack by sending a specially constructed file.
Recommendations For FreeImage version 3.18.0, consider avoiding the use of the StreamCalcIFDSize function in JXRMeta.c until a patch is available, or refrain from processing untrusted JXR files to minimize the risk of exploitation.

Exploit

Fix

DoS

Uncontrolled Recursion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-12212

Affected Products

Debian
Freeimage