CVE-2024-28573: Buffer Overflow
Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to cause a denial of service (DoS) via the jpegreadexifprofile() function when reading images in JPEG format.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-28573?
CVE-2024-28573 is classified as a medium severity vulnerability due to its potential to cause a denial of service.
How do I fix CVE-2024-28573?
To mitigate CVE-2024-28573, it is recommended to upgrade to the latest version of FreeImage that addresses this buffer overflow vulnerability.
What are the potential impacts of CVE-2024-28573?
The primary impact of CVE-2024-28573 is a denial of service, which can lead to application crashes when processing JPEG images.
Who is affected by CVE-2024-28573?
Users and applications utilizing FreeImage version 3.19.0 [r1909] are affected by CVE-2024-28573.
What functions are vulnerable in CVE-2024-28573?
The jpeg_read_exif_profile() function in FreeImage is the specific function that exposes the vulnerability in CVE-2024-28573.