https://seclists.org/oss-sec/2024/q2/97: Re: CWE-121, CWE-122: libfreeimage 3.40-3.18/19+ buffer overflow
Published Apr 11, 2024
·Updated
Affected Software
1 affected component
FreeImage libfreeimage>=3.18<=3.40
Frequently Asked Questions
1
What is the severity of CWE-121, CWE-122 in libfreeimage 3.40-3.18/19?
The severity of CWE-121, CWE-122 in libfreeimage 3.40-3.18/19 is considered high due to the potential for buffer overflow vulnerabilities that can lead to code execution.
2
How do I fix CWE-121, CWE-122 in libfreeimage 3.40-3.18/19?
To fix CWE-121, CWE-122 in libfreeimage 3.40-3.18/19, update to the latest version of libfreeimage where the vulnerabilities have been patched.
3
What impact does CWE-121, CWE-122 have on systems using libfreeimage 3.40-3.18/19?
CWE-121, CWE-122 can allow attackers to exploit buffer overflows, potentially leading to system crashes or arbitrary code execution.
4
Are there any known exploits for CWE-121, CWE-122 in libfreeimage 3.40-3.18/19?
Yes, there are known exploit techniques for CWE-121, CWE-122 that can take advantage of the buffer overflow vulnerabilities in libfreeimage.
5
Who is affected by CWE-121, CWE-122 in libfreeimage 3.40-3.18/19?
Any application or software relying on libfreeimage 3.40-3.18/19 is potentially affected by CWE-121, CWE-122 vulnerabilities.