CVE-2024-28572: Buffer Overflow
Published Mar 20, 2024
·Updated
Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to cause a denial of service (DoS) via the FreeImageSetTagValue() function when reading images in JPEG format.
Affected Software
2 affected components
Freeimage Project Freeimage=3.19.0
FreeImage FreeImage
Event History
Mar 20, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-28572?
CVE-2024-28572 is classified as a moderate severity buffer overflow vulnerability.
2
How do I fix CVE-2024-28572?
To fix CVE-2024-28572, it is recommended to upgrade FreeImage to the latest version that addresses this vulnerability.
3
What type of attack is possible with CVE-2024-28572?
CVE-2024-28572 allows local attackers to execute a denial of service (DoS) attack by manipulating the FreeImage_SetTagValue() function.
4
Which versions of FreeImage are affected by CVE-2024-28572?
CVE-2024-28572 affects FreeImage version 3.19.0 [r1909].
5
What consequences can occur due to CVE-2024-28572?
Exploiting CVE-2024-28572 can lead to unexpected application crashes and service disruptions.