Описание
FreeImage 3.18.0 contains a Use After Free in PluginTARGA.cpp;loadRLE().
A flaw was found in FreeImage. A remote attacker could exploit a Use After Free vulnerability in the PluginTARGA.cpp;loadRLE() function. This could lead to arbitrary code execution, resulting in high impact on the confidentiality, integrity, and availability of the affected system.
Отчет
Red Hat rates the impact of this flaw as "Important", because exploitation requires that a system process untrusted input. This could happen by either fetching an untrusted remote image (requiring user interaction) or by allowing untrusted sources to process their own image.
Дополнительная информация
Статус:
9.8 Critical
CVSS3
Связанные уязвимости
FreeImage 3.18.0 contains a Use After Free in PluginTARGA.cpp;loadRLE().
FreeImage 3.18.0 contains a Use After Free in PluginTARGA.cpp;loadRLE().
FreeImage 3.18.0 contains a Use After Free in PluginTARGA.cpp;loadRLE( ...
FreeImage 3.18.0 contains a Use After Free in PluginTARGA.cpp;loadRLE().
Уязвимость функции loadRLE() загрузчика TGA-изображений (PluginTARGA.cpp) графической библиотеки Freeimage, позволяющая нарушителю вызвать отказ в обслуживании или выполнить произвольный код
9.8 Critical
CVSS3