CVE-2016-5684: High severity Freeimage Project Freeimage vulnerability
An exploitable out-of-bounds write vulnerability exists in the XMP image handling functionality of the FreeImage library. A specially crafted XMP file can cause an arbitrary memory overwrite resulting in code execution. An attacker can provide a malicious image to trigger this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-5684?
CVE-2016-5684 is classified as a critical vulnerability due to the potential for arbitrary memory overwrite and code execution.
How do I fix CVE-2016-5684?
To fix CVE-2016-5684, update to FreeImage version 3.17.0 or later, or ensure you are using the patched versions provided by your distribution.
Which versions of FreeImage are affected by CVE-2016-5684?
FreeImage versions prior to 3.17.0 are affected by CVE-2016-5684 and may lead to exploitation if not updated.
What type of attack is possible with CVE-2016-5684?
CVE-2016-5684 allows for an attack through a specially crafted XMP file that can trigger an out-of-bounds write, resulting in code execution.
How can I determine if my system is vulnerable to CVE-2016-5684?
You can determine if your system is vulnerable by checking if you are running FreeImage version 3.15.4-3ubuntu0.1 or any version prior to 3.17.0.