CVE-2024-28570: Buffer Overflow
Published Mar 20, 2024
·Updated
Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to cause a denial of service (DoS) via the processMakerNote() function when reading images in JPEG format.
Affected Software
2 affected components
Freeimage Project Freeimage=3.19.0
FreeImage FreeImage
Event History
Mar 20, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-28570?
CVE-2024-28570 is classified as a medium severity vulnerability.
2
How do I fix CVE-2024-28570?
To fix CVE-2024-28570, upgrade FreeImage to version 3.19.0 or later that patches this vulnerability.
3
What is the impact of CVE-2024-28570?
CVE-2024-28570 can lead to a denial of service (DoS) when processing JPEG images.
4
Who is affected by CVE-2024-28570?
Any user or application utilizing FreeImage version 3.19.0 [r1909] is potentially affected by CVE-2024-28570.
5
Is CVE-2024-28570 exploitable remotely?
CVE-2024-28570 requires local access to exploit, making it less likely to be exploited remotely.