Vulnerability CVE-2015-0852: Information

Description

Multiple integer underflows in PluginPCX.cpp in FreeImage 3.17.0 and earlier allow remote attackers to cause a denial of service (heap memory corruption) via vectors related to the height and width of a window.

Severity: MEDIUM (5.0)

Published: Sept. 29, 2015
Modified: Jan. 16, 2019
Error type identifier: CWE-189

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
libfreeimagesisyphus3.18.0-alt13.18.0-alt9ALT-PU-2018-2325-1211059Fixed
libfreeimagep103.18.0-alt13.18.0-alt7ALT-PU-2018-2325-1211059Fixed
libfreeimagep93.18.0-alt13.18.0-alt4ALT-PU-2018-2325-1211059Fixed
libfreeimagec10f13.18.0-alt13.18.0-alt7ALT-PU-2018-2325-1211059Fixed
libfreeimagec9f23.18.0-alt13.18.0-alt4ALT-PU-2018-2325-1211059Fixed
libfreeimagep113.18.0-alt13.18.0-alt9ALT-PU-2018-2325-1211059Fixed

References to Advisories, Solutions, and Tools

    1. Configuration 1

      cpe:2.3:a:freeimage_project:freeimage:*:*:*:*:*:*:*:*
      End including
      3.17.0