PT-2024-22477 · Freeimage+1 · Freeimage+1

Published

2024-03-19

·

Updated

2024-08-02

·

CVE-2024-28574

CVSS v3.1

6.2

Medium

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions FreeImage version 3.19.0
Description The issue allows a local attacker to cause a denial of service (DoS) via the opj j2k copy default tcp and create tcd() function when reading images in J2K format.
Recommendations For FreeImage version 3.19.0, consider disabling the opj j2k copy default tcp and create tcd() function as a temporary workaround until a patch is available. Restrict access to J2K image reading functionality to minimize the risk of exploitation.

Exploit

Fix

DoS

Stack Overflow

Weakness Enumeration

Related Identifiers

CVE-2024-28574

Affected Products

Debian
Freeimage