6.5
CVSSv3

CVE-2019-12213

Published: 20/05/2019 Updated: 07/11/2023
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

When FreeImage 3.18.0 reads a special TIFF file, the TIFFReadDirectory function in PluginTIFF.cpp always returns 1, leading to stack exhaustion.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

freeimage project freeimage 3.18.0

canonical ubuntu linux 18.04

debian debian linux 8.0

debian debian linux 9.0

debian debian linux 10.0

fedoraproject fedora 30

fedoraproject fedora 31

Vendor Advisories

It was found that freeimage, a graphics library, was affected by the following two security issues: CVE-2019-12211 Heap buffer overflow caused by invalid memcpy in PluginTIFF This flaw might be leveraged by remote attackers to trigger denial of service or any other unspecified impact via crafted TIFF data CVE-2019-12213 Stack exh ...
Debian Bug report logs - #947478 freeimage: CVE-2019-12214 Package: src:freeimage; Maintainer for src:freeimage is Debian Science Maintainers <debian-science-maintainers@listsaliothdebianorg>; Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Sun, 26 May 2019 19:27:01 UTC Severity: important Tags: security, u ...
Debian Bug report logs - #947477 freeimage: CVE-2019-12212 Package: src:freeimage; Maintainer for src:freeimage is Debian Science Maintainers <debian-science-maintainers@listsaliothdebianorg>; Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Sun, 26 May 2019 19:27:01 UTC Severity: important Tags: security, u ...
Debian Bug report logs - #929597 CVE-2019-12211 CVE-2019-12212 CVE-2019-12213 CVE-2019-12214 Package: src:freeimage; Maintainer for src:freeimage is Debian Science Maintainers <debian-science-maintainers@listsaliothdebianorg>; Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Sun, 26 May 2019 19:27:01 UTC Sev ...