OESA-2023-1898
Dashboard / Vulnerabilities / OESA-2023-1898
Summary: freeimage security update
Details: FreeImage is a library project for developers who would like to support popular graphics image formats (PNG, JPEG, TIFF, BMP and others). Some highlights are: extremely simple in use, not limited to the local PC (unique FreeImageIO) and Plugin driven! Security Fix(es): Buffer Overflow vulnerability in function LoadPixelDataRLE8 in PluginBMP.cpp in FreeImage 3.18.0 allows remote attackers to run arbitrary code and cause other impacts via crafted image file.(CVE-2020-21427) Buffer Overflow vulnerability in function LoadRGB in PluginDDS.cpp in FreeImage 3.18.0 allows remote attackers to run arbitrary code and cause other impacts via crafted image file.(CVE-2020-21428)
References: https://www.openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2023-1898, https://nvd.nist.gov/vuln/detail/CVE-2020-21427, https://nvd.nist.gov/vuln/detail/CVE-2020-21428
Affected packages
Package
Name: freeimage
Purl: pkg:rpm/openEuler/freeimage&distro=openEuler-20.03-LTS-SP1
Affected ranges
Type: ECOSYSTEM
Events:
