Buffer Overflow Vulnerability in FreeImage Open Source Library
CVE-2024-28565

Currently unrated

Key Information:

Vendor

FreeImage

Status
Vendor
CVE Published:
20 March 2024

What is CVE-2024-28565?

A buffer overflow vulnerability exists in the open-source FreeImage library version 3.19.0 [r1909], which can be exploited by local attackers through the psdParser::ReadImageData() function. This vulnerability occurs during the processing of images in PSD (Photoshop Document) format, leading to the possibility of a denial of service (DoS). When a specially crafted PSD file is handled, it can trigger the buffer overflow, potentially allowing an attacker to disrupt service and affect the application's performance.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.