Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-12212

Опубликовано: 20 мая 2019
Источник: nvd
CVSS3: 7.5
CVSS2: 5
EPSS Низкий

Описание

When FreeImage 3.18.0 reads a special JXR file, the StreamCalcIFDSize function of JXRMeta.c repeatedly calls itself due to improper processing of the file, eventually causing stack exhaustion. An attacker can achieve a remote denial of service attack by sending a specially constructed file.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:freeimage_project:freeimage:3.18.0:*:*:*:*:*:*:*

EPSS

Процентиль: 70%
0.0065
Низкий

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-674

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 6 лет назад

When FreeImage 3.18.0 reads a special JXR file, the StreamCalcIFDSize function of JXRMeta.c repeatedly calls itself due to improper processing of the file, eventually causing stack exhaustion. An attacker can achieve a remote denial of service attack by sending a specially constructed file.

CVSS3: 7.5
debian
больше 6 лет назад

When FreeImage 3.18.0 reads a special JXR file, the StreamCalcIFDSize ...

github
больше 3 лет назад

When FreeImage 3.18.0 reads a special JXR file, the StreamCalcIFDSize function of JXRMeta.c repeatedly calls itself due to improper processing of the file, eventually causing stack exhaustion. An attacker can achieve a remote denial of service attack by sending a specially constructed file.

EPSS

Процентиль: 70%
0.0065
Низкий

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-674