buildroot ▾
›
2025.02.x ▾
›
vulnerability
›
CVE-2020-24292
Component Overview
Vulnerability Overview
Name
CVE-2020-24292
Source
NVD (
link
)
Debian (
link
)
Description
Buffer Overflow vulnerability in load function in PluginICO.cpp in FreeImage 3.19.0 [r1859] allows remote attackers to run arbitrary code via opening of crafted ico file.
CWEs
CWE-120
Published Date
Aug 22, 2023
Updated Date
Jun 17, 2026
Workaround
-
Advisories
https://sourceforge.net/p/freeimage/discussion/36111/thread/afb98701eb/
Exploit
https://sourceforge.net/p/freeimage/discussion/36111/thread/afb98701eb/
Exploit
Analysis
#
Affected Component
Analysis
libfreeimage
Patched
Vulnerability Ratings
#
8.8
CVSSv31
NaN
other
Resolved with patches
#
libfreeimage (buildroot:2025.02.x)
#
Title
Author
Resolve
1
Patch #1
Thomas Perale <thomas.perale@mind.be>
CVE-2020-24292