Heap-based buffer overflow in FreeImage - CVE-2019-12211
Published: December 29, 2019 / Updated: August 29, 2023
FreeImage
Detailed vulnerability description
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error within the load() function of the PluginTIFF.cpp file. A remote attacker can can create a specially crafted TIFF file, trigger heap-based buffer overflow and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
How to mitigate CVE-2019-12211
Sources
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PUWVVP67FYM4GMWD7TPQ7C7JPPRUZHYE/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VZ7KBYPPNRMX7RRWVJSX4T63E3TFB6TG/
- https://sourceforge.net/p/freeimage/discussion/36111/thread/e06734bed5/