CVE-2020-21426: Buffer Overflow
Buffer Overflow vulnerability in function CIStream::read in PluginEXR.cpp in FreeImage 3.18.0 allows remote attackers to run arbitrary code and cause other impacts via crafted image file.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-21426?
CVE-2020-21426 is a buffer overflow vulnerability in the C_IStream::read function in PluginEXR.cpp in FreeImage 3.18.0.
What is the severity of CVE-2020-21426?
The severity of CVE-2020-21426 is high with a CVSS score of 7.8.
How does CVE-2020-21426 impact FreeImage?
CVE-2020-21426 allows remote attackers to run arbitrary code and cause other impacts by exploiting the buffer overflow vulnerability in FreeImage.
How can I fix CVE-2020-21426?
To fix CVE-2020-21426, users should update to a patched version of FreeImage 3.18.0 or higher.
Where can I find more information about CVE-2020-21426?
You can find more information about CVE-2020-21426 at the following references: <ul><li><a href="https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RUEK2JOVJBQZVNQIIZZO3JFMTVB4R5KS/">Reference 1</a></li><li><a href="https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UGOMCRAANNCQYJYPPMGRQWKRZGIP6NME/">Reference 2</a></li><li><a href="https://sourceforge.net/p/freeimage/bugs/300/">Reference 3</a></li></ul>