CVE-2024-28574: Buffer Overflow
Published Mar 20, 2024
·Updated
Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to cause a denial of service (DoS) via the opjj2kcopydefaulttcpandcreatetcd() function when reading images in J2K format.
Affected Software
2 affected components
Freeimage Project Freeimage=3.19.0
FreeImage FreeImage
Event History
Mar 20, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-28574?
CVE-2024-28574 has a severity rating that indicates a denial of service risk due to the buffer overflow vulnerability.
2
How do I fix CVE-2024-28574?
To mitigate CVE-2024-28574, it is recommended to upgrade FreeImage to the latest version that addresses the vulnerability.
3
What software is affected by CVE-2024-28574?
CVE-2024-28574 specifically affects FreeImage version 3.19.0.
4
Can CVE-2024-28574 be exploited remotely?
No, CVE-2024-28574 requires local access to exploit the buffer overflow vulnerability.
5
What kind of attack does CVE-2024-28574 facilitate?
CVE-2024-28574 allows a local attacker to cause a denial of service by exploiting the vulnerability during image processing.