First published: Tue Aug 22 2023(Updated: )
Buffer Overflow vulnerability in load function in PluginICO.cpp in FreeImage 3.19.0 [r1859] allows remote attackers to run arbitrary code via opening of crafted ico file.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Freeimage Project Freeimage | =3.19.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-24292 is a buffer overflow vulnerability in the load function in PluginICO.cpp in FreeImage 3.19.0 [r1859].
CVE-2020-24292 allows remote attackers to run arbitrary code by opening a crafted ico file.
CVE-2020-24292 has a severity rating of 8.8 (high).
To fix CVE-2020-24292, you should upgrade to a version of FreeImage that is not affected by this vulnerability.
CVE-2020-24292 is associated with CWE-119 (Improper Restriction of Operations within the Bounds of a Memory Buffer) and CWE-120 (Buffer Copy without Checking Size of Input).