Bug 1214722 (CVE-2020-24295)

Summary: VUL-0: CVE-2020-24295: freeimage: buffer overflow in ReadImageLine() in PSDParser.cpp
Product: [openSUSE] openSUSE Distribution Reporter: Stoyan Manolov <stoyan.manolov>
Component: OtherAssignee: Dominique Leuenberger <dleuenberger>
Status: NEW --- QA Contact: E-mail List <qa-bugs>
Severity: Major    
Priority: P3 - Medium CC: cathy.hu, security-team
Version: Leap 15.5   
Target Milestone: Leap 15.5   
Hardware: Other   
OS: Other   
URL: https://smash.suse.de/issue/375991/
Whiteboard:
Found By: Security Response Team Services Priority:
Business Priority: Blocker: ---
Marketing QA Status: --- IT Deployment: ---

Description Stoyan Manolov 2023-08-29 05:10:41 UTC
CVE-2020-24295

Buffer Overflow vulnerability in PSDParser.cpp::ReadImageLine() in FreeImage 3.19.0 [r1859] allows remote attackers to ru narbitrary code via use of crafted psd file.

Reference:
https://sourceforge.net/p/freeimage/discussion/36111/thread/afb98701eb/

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2020-24295
https://bugzilla.redhat.com/show_bug.cgi?id=2235432
https://www.cve.org/CVERecord?id=CVE-2020-24295
https://sourceforge.net/p/freeimage/discussion/36111/thread/afb98701eb/
Comment 1 Cathy Hu 2023-09-05 11:49:19 UTC
Reassigning to a factory maintainer since the previous assignee is not available and this bug is opensuse-only

Please feel free to assign to another appropriate person or let me know if we should assign it to someone else