Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2023-47994

Опубликовано: 09 янв. 2024
Источник: debian
EPSS Низкий

Описание

An integer overflow vulnerability in LoadPixelDataRLE4 function in PluginBMP.cpp in Freeimage 3.18.0 allows attackers to obtain sensitive information, cause a denial of service and/or run arbitrary code.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
freeimageunfixedpackage
freeimagepostponedtrixiepackage
freeimagepostponedbookwormpackage
freeimagepostponedbullseyepackage
freeimagepostponedbusterpackage

Примечания

  • https://github.com/thelastede/FreeImage-cve-poc/tree/master/CVE-2023-47994

  • https://sourceforge.net/p/freeimage/bugs/359/

EPSS

Процентиль: 40%
0.00185
Низкий

Связанные уязвимости

CVSS3: 8.8
ubuntu
около 2 лет назад

An integer overflow vulnerability in LoadPixelDataRLE4 function in PluginBMP.cpp in Freeimage 3.18.0 allows attackers to obtain sensitive information, cause a denial of service and/or run arbitrary code.

CVSS3: 8.8
nvd
около 2 лет назад

An integer overflow vulnerability in LoadPixelDataRLE4 function in PluginBMP.cpp in Freeimage 3.18.0 allows attackers to obtain sensitive information, cause a denial of service and/or run arbitrary code.

CVSS3: 8.8
github
около 2 лет назад

An integer overflow vulnerability in LoadPixelDataRLE4 function in PluginBMP.cpp in Freeimage 3.18.0 allows attackers to obtain sensitive information, cause a denial of service and/or run arbitrary code.

EPSS

Процентиль: 40%
0.00185
Низкий