Upstream information
Description
Multiple integer underflows in PluginPCX.cpp in FreeImage 3.17.0 and earlier allow remote attackers to cause a denial of service (heap memory corruption) via vectors related to the height and width of a window.Upstream Security Advisories:
- https://www.zerodayinitiative.com/advisories/ZDI-18-1232/
- https://www.zerodayinitiative.com/advisories/ZDI-18-1233/
- https://www.zerodayinitiative.com/advisories/ZDI-18-1234/
- https://www.zerodayinitiative.com/advisories/ZDI-18-1292/
SUSE information
Overall state of this security issue: Resolved
This issue is currently rated as having critical severity.
National Vulnerability Database | |
---|---|
Base Score | 5 |
Vector | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Access Vector | Network |
Access Complexity | Low |
Authentication | None |
Confidentiality Impact | None |
Integrity Impact | None |
Availability Impact | Partial |
List of released packages
Product(s) | Fixed package version(s) | References |
---|---|---|
openSUSE Tumbleweed |
| Patchnames: openSUSE-Tumbleweed-2024-10485 |
SUSE Timeline for this CVE
CVE page created: Fri Aug 28 06:16:20 2015CVE page last modified: Sat Sep 14 11:18:44 2024