CVE-2024-28576
Homebrew vulnerability analysis and mitigation

Overview

CVE-2024-28576 is a buffer overflow vulnerability discovered in FreeImage version 3.19.0 [r1909]. The vulnerability affects the opj_j2k_tcp_destroy() function when processing images in J2K format. This security flaw was disclosed on March 20, 2024, and poses a risk to systems utilizing the affected FreeImage version (NVD).

Technical details

The vulnerability is classified as a buffer overflow issue, specifically occurring in the opj_j2k_tcp_destroy() function of FreeImage. The CVSS v3.1 base score is 5.5 (Medium), with the vector string CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H. The vulnerability is tracked under CWE-120 (Buffer Copy without Checking Size of Input) (NVD).

Impact

When exploited, this vulnerability can lead to a denial of service (DoS) condition. The heap buffer overflow read vulnerability in the opj_j2k_tcp_destroy() function can cause system instability or crashes when processing J2K format images (GitHub Report).

Exploitability

The vulnerability requires local access to exploit, with low attack complexity and low privileges required. No user interaction is necessary for exploitation. The attack can be triggered when processing specially crafted J2K format images through the affected function (NVD).

Mitigation and workarounds

Currently, there are no official fixes available for this vulnerability. Multiple Linux distributions including Debian Bullseye, Bookworm, and Sid remain vulnerable to this issue. Users are advised to monitor for updates and exercise caution when processing J2K format images (Debian Tracker).

Additional resources


SourceThis report was generated using AI

Related Homebrew vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-68968HIGH7.5
  • Homebrew logoHomebrew
  • airflow
NoYesAug 12, 2026
CVE-2026-68971MEDIUM6.5
  • Homebrew logoHomebrew
  • airflow
NoYesAug 12, 2026
CVE-2026-68970MEDIUM6.5
  • Homebrew logoHomebrew
  • airflow
NoYesAug 12, 2026
CVE-2026-68969MEDIUM6.5
  • Homebrew logoHomebrew
  • airflow
NoYesAug 12, 2026
CVE-2026-68076MEDIUM5.4
  • Homebrew logoHomebrew
  • airflow
NoYesAug 12, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management