CVE-2023-47992: Integer Overflow
Published Jan 9, 2024
·Updated
An integer overflow vulnerability in FreeImageIO.cpp::MemoryReadProc in FreeImage 3.18.0 allows attackers to obtain sensitive information, cause a denial-of-service attacks and/or run arbitrary code.
Affected Software
1 affected component
Freeimage Project Freeimage=3.18.0
Event History
Jan 9, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·11:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-47992?
CVE-2023-47992 is considered a high severity vulnerability due to its potential for arbitrary code execution and denial-of-service attacks.
2
How do I fix CVE-2023-47992?
To fix CVE-2023-47992, upgrade to a patched version of FreeImage that addresses the integer overflow vulnerability.
3
What types of attacks can exploit CVE-2023-47992?
CVE-2023-47992 can be exploited to obtain sensitive information, cause denial-of-service attacks, or execute arbitrary code.
4
Which version of FreeImage is affected by CVE-2023-47992?
CVE-2023-47992 specifically affects FreeImage version 3.18.0.
5
What component of FreeImage is vulnerable in CVE-2023-47992?
The vulnerability in CVE-2023-47992 resides in the FreeImageIO.cpp::_MemoryReadProc component.