Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rp8j-g7jf-vmc8

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

When FreeImage 3.18.0 reads a special JXR file, the StreamCalcIFDSize function of JXRMeta.c repeatedly calls itself due to improper processing of the file, eventually causing stack exhaustion. An attacker can achieve a remote denial of service attack by sending a specially constructed file.

When FreeImage 3.18.0 reads a special JXR file, the StreamCalcIFDSize function of JXRMeta.c repeatedly calls itself due to improper processing of the file, eventually causing stack exhaustion. An attacker can achieve a remote denial of service attack by sending a specially constructed file.

EPSS

Процентиль: 70%
0.0065
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 6 лет назад

When FreeImage 3.18.0 reads a special JXR file, the StreamCalcIFDSize function of JXRMeta.c repeatedly calls itself due to improper processing of the file, eventually causing stack exhaustion. An attacker can achieve a remote denial of service attack by sending a specially constructed file.

CVSS3: 7.5
nvd
больше 6 лет назад

When FreeImage 3.18.0 reads a special JXR file, the StreamCalcIFDSize function of JXRMeta.c repeatedly calls itself due to improper processing of the file, eventually causing stack exhaustion. An attacker can achieve a remote denial of service attack by sending a specially constructed file.

CVSS3: 7.5
debian
больше 6 лет назад

When FreeImage 3.18.0 reads a special JXR file, the StreamCalcIFDSize ...

EPSS

Процентиль: 70%
0.0065
Низкий