An exploitable out-of-bounds write vulnerability exists in the XMP image handling functionality of the FreeImage library. A specially crafted XMP file can cause an arbitrary memory overwrite resulting in code execution. An attacker can provide a malicious image to trigger this vulnerability.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-647-1 | freeimage security update |
Debian DSA |
DSA-3692-1 | freeimage security update |
EUVD |
EUVD-2016-6627 | An exploitable out-of-bounds write vulnerability exists in the XMP image handling functionality of the FreeImage library. A specially crafted XMP file can cause an arbitrary memory overwrite resulting in code execution. An attacker can provide a malicious image to trigger this vulnerability. |
Ubuntu USN |
USN-3925-1 | FreeImage vulnerability |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: certcc
Published:
Updated: 2024-08-06T01:08:00.415Z
Reserved: 2016-06-16T00:00:00
Link: CVE-2016-5684
No data.
Status : Deferred
Published: 2017-01-06T21:59:01.727
Modified: 2025-04-20T01:37:25.860
Link: CVE-2016-5684
No data.
OpenCVE Enrichment
No data.
Debian DLA
Debian DSA
EUVD
Ubuntu USN