First published: Fri Jan 06 2017(Updated: )
An exploitable out-of-bounds write vulnerability exists in the XMP image handling functionality of the FreeImage library. A specially crafted XMP file can cause an arbitrary memory overwrite resulting in code execution. An attacker can provide a malicious image to trigger this vulnerability.
Credit: cret@cert.org cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
Freeimage Project Freeimage | =3.17.0 | |
ubuntu/freeimage | <3.15.4-3ubuntu0.1 | 3.15.4-3ubuntu0.1 |
ubuntu/freeimage | <3.17.0+ | 3.17.0+ |
ubuntu/freeimage | <3.17.0+ | 3.17.0+ |
debian/freeimage | 3.18.0+ds2-6+deb11u1 3.18.0+ds2-9+deb12u1 3.18.0+ds2-10 | |
=3.17.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.