PT-2024-22482 · Freeimage+1 · Freeimage+1

Ruanxingzhi

·

Published

2024-03-19

·

Updated

2024-08-05

·

CVE-2024-28579

CVSS v3.1

6.2

Medium

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions FreeImage version 3.19.0
Description The issue allows a local attacker to cause a denial of service (DoS) via the FreeImage Unload() function when reading images in HDR format.
Recommendations For FreeImage version 3.19.0, consider disabling the FreeImage Unload() function when handling HDR images until a patch is available.

Exploit

Fix

DoS

Out of bounds Read

Weakness Enumeration

Related Identifiers

CVE-2024-28579

Affected Products

Debian
Freeimage