
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2024-28576 is a buffer overflow vulnerability discovered in FreeImage version 3.19.0 [r1909]. The vulnerability affects the opj_j2k_tcp_destroy() function when processing images in J2K format. This security flaw was disclosed on March 20, 2024, and poses a risk to systems utilizing the affected FreeImage version (NVD).
The vulnerability is classified as a buffer overflow issue, specifically occurring in the opj_j2k_tcp_destroy() function of FreeImage. The CVSS v3.1 base score is 5.5 (Medium), with the vector string CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H. The vulnerability is tracked under CWE-120 (Buffer Copy without Checking Size of Input) (NVD).
When exploited, this vulnerability can lead to a denial of service (DoS) condition. The heap buffer overflow read vulnerability in the opj_j2k_tcp_destroy() function can cause system instability or crashes when processing J2K format images (GitHub Report).
The vulnerability requires local access to exploit, with low attack complexity and low privileges required. No user interaction is necessary for exploitation. The attack can be triggered when processing specially crafted J2K format images through the affected function (NVD).
Currently, there are no official fixes available for this vulnerability. Multiple Linux distributions including Debian Bullseye, Bookworm, and Sid remain vulnerable to this issue. Users are advised to monitor for updates and exercise caution when processing J2K format images (Debian Tracker).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."