Bug 1214555 (CVE-2020-21426) - VUL-0: CVE-2020-21426: freeimage: Buffer Overflow vulnerability in function C_IStream:read in PluginEXR.cpp in FreeImage 3.18.0 allows remote attackers to run arbitrary code and cause other impacts via crafted image file.
Summary: VUL-0: CVE-2020-21426: freeimage: Buffer Overflow vulnerability in function C...
Status: RESOLVED FIXED
Alias: CVE-2020-21426
Product: openSUSE Backports
Classification: openSUSE
Component: Packages (show other bugs)
Version: SLE-15-SP5
Hardware: Other Other
: P3 - Medium : Normal
Target Milestone: ---
Assignee: Dominique Leuenberger
QA Contact: E-Mail List
URL: https://smash.suse.de/issue/375959/
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2023-08-24 09:08 UTC by Stoyan Manolov
Modified: 2023-10-11 11:44 UTC (History)
2 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Stoyan Manolov 2023-08-24 09:08:32 UTC
CVE-2020-21426

Buffer Overflow vulnerability in function C_IStream::read in PluginEXR.cpp in
FreeImage 3.18.0 allows remote attackers to run arbitrary code and cause other
impacts via crafted image file.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2020-21426
https://www.cve.org/CVERecord?id=CVE-2020-21426
https://sourceforge.net/p/freeimage/bugs/300/
Comment 1 Stoyan Manolov 2023-08-24 09:08:52 UTC
Tracking as Affected:

OpenSUSE:Factory/freeimage
openSUSE:Backports:SLE-15-SP4:Update/freeimage
openSUSE:Backports:SLE-15-SP5:Update/freeimage
Comment 2 Cathy Hu 2023-09-05 11:51:00 UTC
Reassigning to a factory maintainer since the previous assignee is not available and this bug is opensuse-only

Please feel free to assign to another appropriate person or let me know if we should assign it to someone else
Comment 3 OBSbugzilla Bot 2023-10-05 16:34:16 UTC
This is an autogenerated message for OBS integration:
This bug (1214555) was mentioned in
https://build.opensuse.org/request/show/1115869 Factory / freeimage
Comment 4 Dominique Leuenberger 2023-10-11 11:44:54 UTC
(In reply to OBSbugzilla Bot from comment #3)
> This is an autogenerated message for OBS integration:
> This bug (1214555) was mentioned in
> https://build.opensuse.org/request/show/1115869 Factory / freeimage

Resolved