PT-2019-12700 · Freeimage+1 · Freeimage+1
Taolaw
·
Published
2019-05-20
·
Updated
2020-08-24
·
CVE-2019-12212
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
FreeImage version 3.18.0
Description
The issue arises when processing a specially crafted JXR file, causing the StreamCalcIFDSize function in JXRMeta.c to recursively call itself due to improper file handling, leading to stack exhaustion. This can be exploited by an attacker to achieve a remote denial of service attack by sending a specially constructed file.
Recommendations
For FreeImage version 3.18.0, consider avoiding the use of the StreamCalcIFDSize function in JXRMeta.c until a patch is available, or refrain from processing untrusted JXR files to minimize the risk of exploitation.
Exploit
Fix
DoS
Uncontrolled Recursion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Debian
Freeimage