Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2020-24292

Опубликовано: 22 авг. 2023
Источник: debian

Описание

Buffer Overflow vulnerability in load function in PluginICO.cpp in FreeImage 3.19.0 [r1859] allows remote attackers to run arbitrary code via opening of crafted ico file.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
freeimageunfixedpackage
freeimagepostponedtrixiepackage
freeimagepostponedbookwormpackage
freeimagepostponedbullseyepackage

Примечания

  • https://sourceforge.net/p/freeimage/discussion/36111/thread/afb98701eb/

  • Patch in Fedora (not upstream'ed): https://src.fedoraproject.org/rpms/freeimage/blob/f39/f/CVE-2020-24292.patch

Связанные уязвимости

CVSS3: 8.8
ubuntu
больше 2 лет назад

Buffer Overflow vulnerability in load function in PluginICO.cpp in FreeImage 3.19.0 [r1859] allows remote attackers to run arbitrary code via opening of crafted ico file.

CVSS3: 8.8
nvd
больше 2 лет назад

Buffer Overflow vulnerability in load function in PluginICO.cpp in FreeImage 3.19.0 [r1859] allows remote attackers to run arbitrary code via opening of crafted ico file.

CVSS3: 8.8
github
больше 2 лет назад

Buffer Overflow vulnerability in load function in PluginICO.cpp in FreeImage 3.19.0 [r1859] allows remote attackers to run arbitrary code via opening of crafted ico file.