CVE-2024-28576: Buffer Overflow
Published Mar 20, 2024
·Updated
Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to cause a denial of service (DoS) via the opjj2ktcpdestroy() function when reading images in J2K format.
Affected Software
2 affected components
Freeimage Project Freeimage=3.19.0
FreeImage FreeImage
Event History
Mar 20, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-28576?
CVE-2024-28576 has been classified as a moderate severity vulnerability.
2
How do I fix CVE-2024-28576?
To fix CVE-2024-28576, upgrade FreeImage to the latest version that addresses this buffer overflow issue.
3
What type of attack is related to CVE-2024-28576?
CVE-2024-28576 is associated with a local denial of service (DoS) attack when processing J2K format images.
4
What function is vulnerable in CVE-2024-28576?
The vulnerable function in CVE-2024-28576 is opj_j2k_tcp_destroy().
5
Can CVE-2024-28576 be exploited remotely?
No, CVE-2024-28576 requires local access to exploit the buffer overflow vulnerability.