CVE-2024-28575: Buffer Overflow
Published Mar 20, 2024
·Updated
Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to cause a denial of service (DoS) via the opjj2kreadmct() function when reading images in J2K format.
Affected Software
2 affected components
Freeimage Project Freeimage=3.19.0
FreeImage FreeImage
Event History
Mar 20, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-28575?
CVE-2024-28575 is considered a high severity vulnerability due to its potential for causing denial of service.
2
How do I fix CVE-2024-28575?
To fix CVE-2024-28575, upgrade FreeImage to the latest version that addresses this buffer overflow vulnerability.
3
What type of vulnerability is CVE-2024-28575?
CVE-2024-28575 is a buffer overflow vulnerability located in the opj_j2k_read_mct() function.
4
Who is affected by CVE-2024-28575?
CVE-2024-28575 affects users of FreeImage version 3.19.0 [r1909] when handling J2K format images.
5
Can CVE-2024-28575 be exploited remotely?
CVE-2024-28575 requires local access for exploitation, as it affects processing of images by the application.