7.8
CVSSv3

CVE-2020-21426

Published: 22/08/2023 Updated: 07/11/2023
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 0

Vulnerability Summary

Buffer Overflow vulnerability in function C_IStream::read in PluginEXR.cpp in FreeImage 3.18.0 allows remote malicious users to run arbitrary code and cause other impacts via crafted image file.

Vulnerable Product Search on Vulmon Subscribe to Product

freeimage project freeimage 3.18.0

Vendor Advisories

Debian Bug report logs - #1051736 freeimage: CVE-2020-21426 Package: src:freeimage; Maintainer for src:freeimage is Debian Science Maintainers <debian-science-maintainers@listsaliothdebianorg>; Reported by: Moritz Mühlenhoff <jmm@inutilorg> Date: Mon, 11 Sep 2023 21:03:02 UTC Severity: important Tags: security, ...