CVE-2024-28563: Buffer Overflow
Published Mar 20, 2024
·Updated
Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to cause a denial of service (DoS) via the Imf22::DwaCompressor::Classifier::Classifier() function when reading images in EXR format.
Affected Software
2 affected components
Freeimage Project Freeimage=3.19.0
FreeImage FreeImage
Event History
Mar 20, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-28563?
CVE-2024-28563 has a high severity rating due to its potential to cause denial of service attacks.
2
How do I fix CVE-2024-28563?
To fix CVE-2024-28563, upgrade to a patched version of FreeImage that addresses this vulnerability.
3
What does CVE-2024-28563 affect?
CVE-2024-28563 affects FreeImage version 3.19.0, specifically when processing EXR format images.
4
Can CVE-2024-28563 be exploited remotely?
CVE-2024-28563 is a local vulnerability, meaning it requires local access to exploit.
5
What kinds of attacks can CVE-2024-28563 facilitate?
CVE-2024-28563 could lead to denial of service attacks by causing application crashes when handling certain image inputs.