PT-2024-22484 · Freeimage+1 · Freeimage+1

Published

2024-03-19

·

Updated

2024-08-02

·

CVE-2024-28580

CVSS v3.1

8.4

High

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions FreeImage version 3.19.0
Description The issue allows a local attacker to execute arbitrary code via the ReadData() function when reading images in RAS format.
Recommendations For FreeImage version 3.19.0, consider disabling the ReadData() function when handling RAS format images until a patch is available. Restrict access to image processing functions to minimize the risk of exploitation.

Exploit

Fix

Stack Overflow

Weakness Enumeration

Related Identifiers

CVE-2024-28580

Affected Products

Debian
Freeimage