CVE-2024-28566: Buffer Overflow
Published Mar 20, 2024
·Updated
Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to execute arbitrary code via the AssignPixel() function when reading images in TIFF format.
Affected Software
2 affected components
Freeimage Project Freeimage=3.19.0
FreeImage FreeImage
Event History
Mar 20, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-28566?
CVE-2024-28566 has been classified with a high severity due to its potential for remote code execution.
2
How do I fix CVE-2024-28566?
To fix CVE-2024-28566, update to a patched version of FreeImage that addresses the buffer overflow vulnerability.
3
What systems are affected by CVE-2024-28566?
CVE-2024-28566 affects FreeImage version 3.19.0.
4
Can CVE-2024-28566 be exploited remotely?
CVE-2024-28566 is primarily a local vulnerability that an attacker can exploit by running code on the affected system.
5
What type of vulnerability is CVE-2024-28566?
CVE-2024-28566 is a buffer overflow vulnerability specifically related to the AssignPixel() function in FreeImage.