CVE-2015-0852
freeimage - security update
EPSS 3.0%
描述
Multiple integer underflows in PluginPCX.cpp in FreeImage 3.17.0 and earlier allow remote attackers to cause a denial of service (heap memory corruption) via vectors related to the height and width of a window.
如何修補 CVE-2015-0852
要修補 CVE-2015-0852,請將受影響套件升級到下列已修補版本。
- Debian/freeimage—升級至 3.15.4-5 或更新版本
- Debian/freeimage—升級至 3.10.0-4+deb6u1 或更新版本
- Debian/freeimage—升級至 3.15.1-1.1 或更新版本
CVE-2015-0852 正在被利用嗎?
低 — EPSS 為 3.0%,目前沒有觀察到大規模利用活動。
受影響套件(3)
- from 0, < 3.15.4-5
- from 0, < 3.10.0-4+deb6u1
- from 0, < 3.15.1-1.1