CVE-2016-5684 PUBLISHED

An exploitable out-of-bounds write vulnerability exists in the XMP image handling functionality of the FreeImage library. A specially crafted XMP file can cause an arbitrary memory overwrite resulting in code execution. An attacker can provide a malicious image to trigger this vulnerability.

EPSS 0.50% · 65.6th percentile

Risk Scores

EPSS Score
0.50%
65.6th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSfreeimage3.17.0+ds1-2, *, 0
Ubuntu:14.04:LTSfreeimage0, 3.15.1-2build1, 3.15.4-2

Timeline

References

Open in Interactive Console →