CVE-2019-12211: High severity Freeimage Project Freeimage vulnerability
Last updated 25 August 2025
Other sources
When FreeImage 3.18.0 reads a tiff file, it will be handed to the Load function of the PluginTIFF.cpp file, but a memcpy occurs in which the destination address and the size of the copied data are not considered, resulting in a heap overflow.
— Launchpad
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
CVE-2019-12211
What is the severity of CVE-2019-12211?
The severity of CVE-2019-12211 is high with a severity value of 7.5.
What is the affected software for CVE-2019-12211?
The affected software for CVE-2019-12211 includes FreeImage version up to exclusive 3.15.4-3ubuntu0.1+, 3.17.0+, and 3.18.0+ds2-1+deb10u1, 3.18.0+ds2-6, 3.18.0+ds2-9, and 3.18.0+ds2-10.
How can I fix the vulnerability CVE-2019-12211?
To fix CVE-2019-12211, it is recommended to update FreeImage to version 3.15.4-3ubuntu0.1+ (or higher), 3.17.0+ (or higher), or 3.18.0+ds2-1+deb10u1 (or higher).
Is there any additional information about CVE-2019-12211?
Yes, you can find additional information about CVE-2019-12211 in the references: [1](https://lists.debian.org/debian-lts-announce/2019/12/msg00012.html), [2](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PUWVVP67FYM4GMWD7TPQ7C7JPPRUZHYE/), [3](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VZ7KBYPPNRMX7RRWVJSX4T63E3TFB6TG/).