CVE-2024-31570
CRITICALFreeImage 3.4.0-3.18.0 - Stack-based Buffer Overflow in XPM Load Function
Title source: llmDescription
libfreeimage in FreeImage 3.4.0 through 3.18.0 has a stack-based buffer overflow in the PluginXPM.cpp Load function via an XPM file.
References (2)
Core 2
Core References
Permissions Required
https://sourceforge.net/p/freeimage/bugs/355/
Mailing List, Third Party Advisory
https://www.openwall.com/lists/oss-security/2024/04/11/10
Scores
CVSS v3
9.8
EPSS
0.0059
EPSS Percentile
43.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
total
Details
CWE
CWE-121
CWE-787
Status
published
Products (1)
freeimage_project/freeimage
3.4.0 - 3.18.0
Published
Sep 19, 2024
Tracked Since
Feb 18, 2026