VDB
CVE-2020-21427
CVE-2020-21427
PUBLISHED
CVSS 7.800000190734863 HIGH
Buffer Overflow vulnerability in function LoadPixelDataRLE8 in PluginBMP.cpp in FreeImage 3.18.0 allows remote attackers to run arbitrary code and cause other impacts via crafted image file.
EPSS 0.52% · 42.4th percentile
Risk Scores
CVSS 3.1
7.800000190734863
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
0.52%
42.4th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ubuntu:24.04:LTS | freeimage | 3.18.0+ds2-10build3, 3.18.0+ds2-9.1, 3.18.0+ds2-10 |
| Ubuntu:Pro:18.04:LTS | freeimage | 3.17.0+ds1-5build2, 3.17.0+ds1-5+deb9u1build0.18.04.1, 0 |
| Ubuntu:Pro:14.04:LTS | freeimage | 3.15.4-3, 0, 3.15.1-2build1 |
| Ubuntu:25.10 | freeimage | *, 0 |
| Ubuntu:22.04:LTS | freeimage | 0, 3.18.0+ds2-6ubuntu4, 3.18.0+ds2-6ubuntu3 |
| Ubuntu:Pro:16.04:LTS | freeimage | 3.17.0+ds1-2ubuntu0.1, 3.15.4-6, 0 |
| Ubuntu:20.04:LTS | freeimage | 3.18.0+ds2-1ubuntu2, *, 3.18.0+ds2-1ubuntu3 |
Timeline
- Aug 22, 2023 CVE Published
- Aug 23, 2023 EPSS Score
- Sep 25, 2023 EPSS Score
- Oct 29, 2023 EPSS Score
- Dec 1, 2023 EPSS Score
- Jan 3, 2024 EPSS Score
- Mar 10, 2024 EPSS Score
- Apr 12, 2024 EPSS Score
- May 16, 2024 EPSS Score
- Jun 18, 2024 EPSS Score
- Jul 21, 2024 EPSS Score
- Aug 24, 2024 EPSS Score
References
- https://ubuntu.com/security/CVE-2020-21427 third-party-advisory
- https://sourceforge.net/p/freeimage/bugs/298/ third-party-advisory
- https://ubuntu.com/security/notices/USN-6586-1 vendor-advisory
- https://www.cve.org/CVERecord?id=CVE-2020-21427 third-party-advisory