Daniel Rosser - 2026-09-07

SVN-style unified diff against FreeImage trunk r1911 is attached (CVE-2020-22524, PluginPFM.cpp Load 32-bit 3*width overflow before malloc).

This is the earlier GitHub fix: https://github.com/danoli3/FreeImage/commit/668385e / PR https://github.com/danoli3/FreeImage/pull/56

Siblings just posted for the 2020 ICO/PSD heap overflows: 170, 171, 172. Original ICO/PSD report: https://sourceforge.net/p/freeimage/discussion/36111/thread/afb98701eb/

Apply from the FreeImage tree root: patch -p0 < CVE-2020-22524.patch