Bug 1214776 (CVE-2020-22524) - VUL-0: CVE-2020-22524: freeimage: buffer overflow in FreeImage_Load() in Plugin.cpp
Summary: VUL-0: CVE-2020-22524: freeimage: buffer overflow in FreeImage_Load() in Plug...
Status: RESOLVED FIXED
Alias: CVE-2020-22524
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Normal
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/375981/
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2023-08-30 07:49 UTC by Thomas Leroy
Modified: 2024-05-29 12:20 UTC (History)
2 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Thomas Leroy 2023-08-30 07:49:32 UTC
CVE-2020-22524

Buffer Overflow vulnerability in FreeImage_Load function in FreeImage Library 3.19.0(r1828) allows attackers to cuase a denial of service via crafted PFM file.

Reference:
https://sourceforge.net/p/freeimage/bugs/319/

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2020-22524
https://bugzilla.redhat.com/show_bug.cgi?id=2235356
https://www.cve.org/CVERecord?id=CVE-2020-22524
https://sourceforge.net/p/freeimage/bugs/319/
Comment 1 Thomas Leroy 2023-08-30 07:52:42 UTC
@Dominique, I assigned the bug to you since you added the last change in the package, and freeimage doesn't have a maintainer and bugowner. Feel free to reassign to someone you think is a better fit
Comment 2 OBSbugzilla Bot 2023-10-05 16:34:20 UTC
This is an autogenerated message for OBS integration:
This bug (1214776) was mentioned in
https://build.opensuse.org/request/show/1115869 Factory / freeimage
Comment 3 Robert Frohl 2024-05-29 12:20:44 UTC
done, closing