MEDIUM · 5.0

CVE-2015-0852

Multiple integer underflows in PluginPCX.cpp in FreeImage 3.17.0 and earlier allow remote attackers to cause a denial of service (heap memory corruption) via vectors related to the height and width of...

Vulnerability Description

Multiple integer underflows in PluginPCX.cpp in FreeImage 3.17.0 and earlier allow remote attackers to cause a denial of service (heap memory corruption) via vectors related to the height and width of a window.

CVSS Score

5.0

MEDIUM

AV:N/AC:L/Au:N/C:N/I:N/A:P
Confidentiality
NONE
Integrity
NONE
Availability
PARTIAL

Affected Products

VendorProductVersions
Freeimage ProjectFreeimage<= 3.17.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2015-0852?

CVE-2015-0852 is a vulnerability with a CVSS score of 5.0 (MEDIUM). Multiple integer underflows in PluginPCX.cpp in FreeImage 3.17.0 and earlier allow remote attackers to cause a denial of service (heap memory corruption) via vectors related to the height and width of...

How severe is CVE-2015-0852?

CVE-2015-0852 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2015-0852?

Check the references section above for vendor advisories and patch information. Affected products include: Freeimage Project Freeimage.