Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to execute arbitrary code via the Imf_2_2::copyIntoFrameBuffer() component when reading images in EXR format.
The product writes data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://github.com/Ruanxingzhi/vul-report/tree/master/freeimage-r1909 | third party advisory exploit |
http://www.openwall.com/lists/oss-security/2024/04/11/3 | mailing list third party advisory |
http://www.openwall.com/lists/oss-security/2024/04/11/10 | mailing list third party advisory |
http://www.openwall.com/lists/oss-security/2024/04/11/2 | mailing list third party advisory |