PT-2024-22487 · Freeimage+1 · Freeimage+1

Published

2024-03-19

·

Updated

2024-08-05

·

CVE-2024-28583

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions FreeImage version 3.19.0
Description The issue allows a local attacker to execute arbitrary code via the readLine() function when reading images in XPM format.
Recommendations For FreeImage version 3.19.0, consider disabling the readLine() function when reading XPM images until a patch is available. Restrict access to XPM image processing to minimize the risk of exploitation.

Exploit

Fix

Buffer Overflow

Weakness Enumeration

Related Identifiers

CVE-2024-28583

Affected Products

Debian
Freeimage