Your submission was sent successfully! Close

You have successfully unsubscribed! Close

CVE-2019-12214

Published: 20 May 2019

In FreeImage 3.18.0, an out-of-bounds access occurs because of mishandling of the OpenJPEG j2k_read_ppm_v3 function in j2k.c. The value of l_N_ppm comes from the file read in, and the code does not consider that l_N_ppm may be greater than the size of p_header_data.

Notes

AuthorNote
ebarretto
No fix available as of 2019-09-06.

Priority

Medium

Cvss 3 Severity Score

7.5

Score breakdown

Status

Package Release Status
freeimage
Launchpad, Ubuntu, Debian
bionic Deferred
(2019-09-06)
cosmic Ignored
(reached end-of-life)
disco Ignored
(reached end-of-life)
eoan Ignored
(reached end-of-life)
focal Deferred
(2019-09-06)
groovy Ignored
(reached end-of-life)
hirsute Ignored
(reached end-of-life)
impish Ignored
(reached end-of-life)
jammy Deferred
(2019-09-06)
kinetic Deferred
(2019-09-06)
lunar Deferred
(2019-09-06)
trusty Deferred
(2019-09-06)
upstream Needs triage

xenial Deferred
(2019-09-06)

Severity score breakdown

Parameter Value
Base score 7.5
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Scope Unchanged
Confidentiality None
Integrity impact None
Availability impact High
Vector CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H