8.8
CVSSv3

CVE-2023-47994

Published: 09/01/2024 Updated: 16/01/2024
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

An integer overflow vulnerability in LoadPixelDataRLE4 function in PluginBMP.cpp in Freeimage 3.18.0 allows malicious users to obtain sensitive information, cause a denial of service and/or run arbitrary code.

Vulnerable Product Search on Vulmon Subscribe to Product

freeimage project freeimage 3.18.0

Vendor Advisories

Debian Bug report logs - #1060691 freeimage: CVE-2023-47992 CVE-2023-47993 CVE-2023-47994 CVE-2023-47996 CVE-2023-47997 Package: src:freeimage; Maintainer for src:freeimage is Debian Science Maintainers <debian-science-maintainers@listsaliothdebianorg>; Reported by: Moritz Mühlenhoff <jmm@inutilorg> Date: Fri, 12 ...