Null Pointer Dereference in FreeImage Affects Image Processing Functionality
CVE-2024-28577

Currently unrated

Key Information:

Vendor

FreeImage

Status
Vendor
CVE Published:
20 March 2024

What is CVE-2024-28577?

A Null Pointer Dereference vulnerability has been identified in FreeImage version 3.19.0 [r1909]. This flaw can be exploited by a local attacker to trigger a denial of service condition when processing JPEG images via the jpeg_read_exif_profile_raw() function. Successful exploitation may lead to application crashes, impacting the availability of the image processing service.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.