CVE-2019-12213: Medium severity Freeimage Project Freeimage vulnerability
Last updated 25 August 2025
Other sources
When FreeImage 3.18.0 reads a special TIFF file, the TIFFReadDirectory function in PluginTIFF.cpp always returns 1, leading to stack exhaustion.
— Launchpad
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2019-12213.
What is the severity of CVE-2019-12213?
The severity of CVE-2019-12213 is medium.
What software versions are affected by CVE-2019-12213?
Versions 3.17.0 and above of FreeImage on Ubuntu, versions 3.15.4-3ubuntu0.1 and above of FreeImage on Trusty, versions 3.18.0+ds2-1+deb10u1, 3.18.0+ds2-6, 3.18.0+ds2-9, and 3.18.0+ds2-10 of FreeImage on Debian, and FreeImage version 3.18.0 from the FreeImage Project are affected.
How do I fix CVE-2019-12213?
To fix CVE-2019-12213, update FreeImage to version 3.17.0 or later on Ubuntu, version 3.15.4-3ubuntu0.1 or later on Trusty, or any of the fixed versions (3.18.0+ds2-1+deb10u1, 3.18.0+ds2-6, 3.18.0+ds2-9, or 3.18.0+ds2-10) on Debian.
What is the Common Weakness Enumeration (CWE) ID of CVE-2019-12213?
The Common Weakness Enumeration (CWE) ID of CVE-2019-12213 is CWE-674.