CVE-2020-21427
Published: 22 August 2023
Buffer Overflow vulnerability in function LoadPixelDataRLE8 in PluginBMP.cpp in FreeImage 3.18.0 allows remote attackers to run arbitrary code and cause other impacts via crafted image file.
Priority
Status
Package | Release | Status |
---|---|---|
freeimage Launchpad, Ubuntu, Debian |
bionic |
Released
(3.17.0+ds1-5+deb9u1ubuntu0.1~esm1)
Available with Ubuntu Pro |
focal |
Released
(3.18.0+ds2-1ubuntu3.1)
|
|
jammy |
Released
(3.18.0+ds2-6ubuntu5.1)
|
|
lunar |
Released
(3.18.0+ds2-9ubuntu0.1)
|
|
mantic |
Released
(3.18.0+ds2-9.1ubuntu0.1)
|
|
trusty |
Released
(3.15.4-3ubuntu0.1+esm3)
Available with Ubuntu Pro or Ubuntu Pro (Infra-only) |
|
upstream |
Needs triage
|
|
xenial |
Released
(3.17.0+ds1-2ubuntu0.1+esm1)
Available with Ubuntu Pro |
Severity score breakdown
Parameter | Value |
---|---|
Base score | 7.8 |
Attack vector | Local |
Attack complexity | Low |
Privileges required | None |
User interaction | Required |
Scope | Unchanged |
Confidentiality | High |
Integrity impact | High |
Availability impact | High |
Vector | CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |