7.5
CVSSv3

CVE-2019-12211

Published: 20/05/2019 Updated: 07/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

When FreeImage 3.18.0 reads a tiff file, it will be handed to the Load function of the PluginTIFF.cpp file, but a memcpy occurs in which the destination address and the size of the copied data are not considered, resulting in a heap overflow.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

freeimage project freeimage 3.18.0

canonical ubuntu linux 18.04

Vendor Advisories

It was found that freeimage, a graphics library, was affected by the following two security issues: CVE-2019-12211 Heap buffer overflow caused by invalid memcpy in PluginTIFF This flaw might be leveraged by remote attackers to trigger denial of service or any other unspecified impact via crafted TIFF data CVE-2019-12213 Stack exh ...
Debian Bug report logs - #947478 freeimage: CVE-2019-12214 Package: src:freeimage; Maintainer for src:freeimage is Debian Science Maintainers <debian-science-maintainers@listsaliothdebianorg>; Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Sun, 26 May 2019 19:27:01 UTC Severity: important Tags: security, u ...
Debian Bug report logs - #947477 freeimage: CVE-2019-12212 Package: src:freeimage; Maintainer for src:freeimage is Debian Science Maintainers <debian-science-maintainers@listsaliothdebianorg>; Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Sun, 26 May 2019 19:27:01 UTC Severity: important Tags: security, u ...
Debian Bug report logs - #929597 CVE-2019-12211 CVE-2019-12212 CVE-2019-12213 CVE-2019-12214 Package: src:freeimage; Maintainer for src:freeimage is Debian Science Maintainers <debian-science-maintainers@listsaliothdebianorg>; Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Sun, 26 May 2019 19:27:01 UTC Sev ...