CVE-2024-9029
CVSS 3.1 Score 7.5 of 10 (high)
Details
Published Sep 27, 2024
Updated: Sep 30, 2024
CWE ID 126
Summary
CVE-2024-9029 is a newly identified vulnerability affecting the freeimage library. Maliciously crafted images can trigger a buffer over-read of one byte in the read_iptc_profile function located in the Source/Metadata/IPTC.cpp file. The size of the profile is not being properly sanitized, leading to a crash in applications linked to the library. This crash results in a denial of service. Users are encouraged to update their freeimage library to a patched version to mitigate this issue.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.