https://seclists.org/oss-sec/2024/q2/89: CWE-121, CWE-122: libfreeimage 3.40-3.18/19+ buffer overflow
Published Apr 11, 2024
·Updated
Affected Software
1 affected component
FreeImage libfreeimage>=3.18<3.40
Frequently Asked Questions
1
What is the severity of CWE-121 and CWE-122 related to libfreeimage 3.40-3.18/19?
CWE-121 and CWE-122 vulnerabilities in libfreeimage 3.40-3.18/19 are classified as high severity due to potential buffer overflow risks.
2
How do I fix CWE-121 and CWE-122 vulnerabilities in libfreeimage?
To fix CWE-121 and CWE-122 vulnerabilities in libfreeimage, update to the latest version of the library where the vulnerabilities have been resolved.
3
What kind of impact do CWE-121 and CWE-122 vulnerabilities have on libfreeimage users?
CWE-121 and CWE-122 vulnerabilities can lead to denial of service and arbitrary code execution, compromising the security and stability of affected systems.
4
When were CWE-121 and CWE-122 vulnerabilities reported for libfreeimage?
CWE-121 and CWE-122 vulnerabilities in libfreeimage were reported on April 11, 2024.
5
Who is affected by CWE-121 and CWE-122 vulnerabilities in libfreeimage?
Users and applications relying on affected versions of libfreeimage, specifically versions 3.40-3.18/19, are at risk from CWE-121 and CWE-122 vulnerabilities.