Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

Debian Buster DLA-3662-1: freeimage critical buffer overflow issues

debian lts
Calendar Grey November 25, 2023
Dist Debian Esm H88
Prompt application of updates is vital because of critical buffer overflow vulnerabilities in FreeImage that allow for unauthorized remote code execution.
Multiple vulnerabilities were discovered in freeimage, library for graphics image formats

Summary

CVE-2020-21427
Buffer overflow vulnerability in function LoadPixelDataRLE8
in PluginBMP.cpp allows remote attackers to run arbitrary code and cause
other impacts via crafted image file.

CVE-2020-21428
Buffer overflow vulnerability in function LoadRGB in
PluginDDS.cpp allows remote attackers to run arbitrary code and cause other
impacts via crafted image file.

CVE-2020-22524
Buffer overflow vulnerability in FreeImage_Load function
allows remote attackers to run arbitrary code and cause other
impacts via crafted PFM file.

For Debian 10 buster, these problems have been fixed in version
3.18.0+ds2-1+deb10u2.

We recommend that you upgrade your freeimage packages.

For the detailed security status of freeimage please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/source-package/freeimage

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be

Read the Full Advisory


Severity
critical
Lowest
Low
Medium
High
Critical

Package: freeimage
Version: 3.18.0+ds2-1+deb10u2
CVE ID: CVE-2020-21427 CVE-2020-21428 CVE-2020-22524

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here