PT-2023-11667 · Freeimage+1 · Freeimage+1

Avscx

·

Published

2023-08-22

·

Updated

2024-11-01

·

CVE-2020-24292

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions FreeImage version 3.19.0
Description A Buffer Overflow issue exists in the load function in PluginICO.cpp, allowing remote attackers to run arbitrary code via the opening of crafted ico files.
Recommendations For FreeImage version 3.19.0, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Buffer Overflow

Weakness Enumeration

Related Identifiers

CVE-2020-24292
OESA-2024-2305

Affected Products

Debian
Freeimage