CVE-2015-0852: Medium severity Freeimage Project Freeimage vulnerability
Published Aug 28, 2015
·Updated
Multiple integer underflows in PluginPCX.cpp in FreeImage 3.17.0 and earlier allow remote attackers to cause a denial of service (heap memory corruption) via vectors related to the height and width of a window.
Affected Software
2 affected componentsFixes available
debian/freeimage
3.18.0+ds2-6+deb11u13.18.0+ds2-9+deb12u13.18.0+ds2-10
Freeimage Project Freeimage<=3.17.0
Remediation
Patch Available
Patch Available
Event History
Aug 28, 2015
Data Sourced
via Debian·08:33 AM
SeverityAffected Software
Sep 29, 2015
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Data Sourced
via NVD·06:59 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2015-0852?
CVE-2015-0852 has a severity level that indicates it can lead to denial of service due to heap memory corruption.
2
How do I fix CVE-2015-0852?
To fix CVE-2015-0852, upgrade to FreeImage version 3.18.0 or later.
3
Which versions of FreeImage are affected by CVE-2015-0852?
FreeImage versions up to and including 3.17.0 are affected by CVE-2015-0852.
4
What type of vulnerability is CVE-2015-0852?
CVE-2015-0852 is classified as an integer underflow vulnerability.
5
Can CVE-2015-0852 be exploited remotely?
Yes, CVE-2015-0852 can be exploited remotely by attackers, leading to denial of service.