PT-2024-24140 · Freeimage+2 · Freeimage+2

Michael Knap

·

Published

2024-09-19

·

Updated

2024-09-25

·

CVE-2024-31570

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions FreeImage versions 3.4.0 through 3.18.0
Description The issue is a stack-based buffer overflow in the PluginXPM.cpp Load function via an XPM file. This occurs in the libfreeimage library.
Recommendations For versions 3.4.0 through 3.18.0, consider disabling the Load function in PluginXPM.cpp to prevent exploitation until a patch is available. Restrict access to XPM files to minimize the risk of triggering the buffer overflow.

Fix

Memory Corruption

Stack Overflow

Weakness Enumeration

Related Identifiers

CVE-2024-31570

Affected Products

Debian
Freeimage
Libfreeimage