CVE-2024-9029

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Sep 27, 2024
Updated: Sep 30, 2024
CWE ID 126

Summary

CVE-2024-9029 is a newly identified vulnerability affecting the freeimage library. Maliciously crafted images can trigger a buffer over-read of one byte in the read_iptc_profile function located in the Source/Metadata/IPTC.cpp file. The size of the profile is not being properly sanitized, leading to a crash in applications linked to the library. This crash results in a denial of service. Users are encouraged to update their freeimage library to a patched version to mitigate this issue.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share