Security Advisory

CVE-2016-5684

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2017-01-06 21:00:00
Last updated 2024-08-06 01:08:00
Assigner certcc
CVSS score not scored
State PUBLISHED

Description

An exploitable out-of-bounds write vulnerability exists in the XMP image handling functionality of the FreeImage library. A specially crafted XMP file can cause an arbitrary memory overwrite resulting in code execution. An attacker can provide a malicious image to trigger this vulnerability.