Buffer Overflow Vulnerability in FreeImage by FreeImage Developers
CVE-2020-24295

8.8HIGH

Key Information:

Status
Vendor
CVE Published:
22 August 2023

What is CVE-2020-24295?

A buffer overflow vulnerability exists in the FreeImage library within the ReadImageLine() function of PSDParser.cpp. This flaw enables remote attackers to potentially execute arbitrary code on the affected system by manipulating a crafted PSD file. Proper input validation measures are essential to mitigate risk associated with this vulnerability, as exploitation may lead to unauthorized actions performed on the system.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.