CVE-2016-5684

Severity CVSS v4.0:
Pending analysis
Type:
CWE-787 Out-of-bounds Write
Publication date:
06/01/2017
Last modified:
20/04/2025

Description

An exploitable out-of-bounds write vulnerability exists in the XMP image handling functionality of the FreeImage library. A specially crafted XMP file can cause an arbitrary memory overwrite resulting in code execution. An attacker can provide a malicious image to trigger this vulnerability.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:freeimage_project:freeimage:3.17.0:*:*:*:*:*:*:*