Boletines de Vulnerabilidades

DSA-3392 freeimage - security update


Información sobre el sistema

   
Software afectado Debian

Descripción

Pengsu Cheng discovered that FreeImage, a library for graphic imageformats, contained multiple integer underflows that could lead to adenial of service: remote attackers were able to trigger a crash bysupplying a specially crafted image.

More info:

https://www.debian.org/security/2015/dsa-3392

Identificadores estándar

Propiedad Valor
CVE CVE-2015-0852 and DSA-3392.

Histórico de versiones

Versión Comentario Fecha
1.0 Advisory issued 2015-11-05

Miembros de

Ministerio de Defensa
CNI
CCN
CCN-CERT