Integer Overflow Vulnerability in FreeImage Plugin from FreeImage Project
CVE-2023-47994

8.8HIGH

Key Information:

Status
Vendor
CVE Published:
9 January 2024

What is CVE-2023-47994?

An integer overflow vulnerability within the LoadPixelDataRLE4 function located in PluginBMP.cpp of FreeImage version 3.18.0 enables attackers to exploit the flaw, potentially leading to serious security risks such as the exposure of sensitive information, execution of arbitrary code, and denial of service conditions. This vulnerability underscores the importance of timely updates and security practices for users of FreeImage.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.