PT-2024-13535 · Freeimage+1 · Freeimage+1

Published

2024-01-09

·

Updated

2024-11-01

·

CVE-2023-47995

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions FreeImage version 3.18.0
Description The issue is related to memory allocation with excessive size value in the FreeImage AllocateBitmap function in BitmapAccess.cpp. This allows attackers to cause a denial of service. The estimated number of potentially affected devices worldwide is not available. There is no information about real-world incidents where this issue was exploited.
Recommendations For FreeImage version 3.18.0, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Buffer Overflow

Weakness Enumeration

Related Identifiers

CVE-2023-47995
MGASA-2024-0087
OESA-2024-2305

Affected Products

Debian
Freeimage