CVE-2024-26540: Buffer Overflow
Published Mar 15, 2024
·Updated
A heap-based buffer overflow in Clmg before 3.3.3 can occur via a crafted file to cimglibrary::CImg<unsigned char>::loadanalyze.
Affected Software
3 affected componentsFixes available
CImg cimg<3.3.3
debian/cimg<=2.9.4+dfsg-2, <=3.2.1+dfsg-1
3.5.2+dfsg-1
CImg cimg<3.3.3
Event History
Mar 15, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·01:15 AM
DescriptionSeverityWeakness
Apr 15, 2025
Data Sourced
via Launchpad·06:46 AM
Description
Apr 19, 2025
Data Sourced
via Ubuntu·06:45 AM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-26540?
CVE-2024-26540 is classified as a high-severity vulnerability due to its potential for exploitation leading to arbitrary code execution.
2
How do I fix CVE-2024-26540?
To mitigate CVE-2024-26540, users should upgrade to CImg version 3.3.3 or later, which includes a patch for the buffer overflow vulnerability.
3
What causes CVE-2024-26540?
CVE-2024-26540 is caused by a heap-based buffer overflow that can occur during the loading of crafted files in versions prior to 3.3.3 of CImg.
4
Which versions of CImg are affected by CVE-2024-26540?
CVE-2024-26540 affects all versions of CImg prior to 3.3.3.
5
Is there a workaround for CVE-2024-26540?
While upgrading is recommended, there are no known effective workarounds for CVE-2024-26540 other than avoiding the use of affected versions.