Daniel Rosser - 2026-09-07

Index of the SVN r1911 CVE patch series from danoli3/FreeImage (GitHub 3.19.14 + follow-ups). Apply from the FreeImage tree root with: patch -p0 < CVE-....patch

Already on this tracker:

  • 170 CVE-2020-24292 ICO LoadStandardIcon

  • 171 CVE-2020-24293 psdThumbnail::Read

  • 172 CVE-2020-24295 ReadImageLine

  • 173 CVE-2020-22524 PFM integer overflow

  • 174 (this ticket) CVE-2020-24294 / CVE-2024-28565 UnpackRLE

  • 175 CVE-2024-28579 / CVE-2024-28582 HDR

  • 176 CVE-2024-28584 J2K NULL

  • 177 CVE-2024-28581 TARGA IOCache

  • 178 CVE-2024-28567 TIFF ICC UAF

  • 179 CVE-2021-33367 Exif IFD bound

  • 180 CVE-2024-28568/9029/28570/28573/28577/28578/28580 IPTC/Exif/XPM/RAS

  • 181 CVE-2024-28566/28571/28572/28583 TIFF AssignPixel / JPEG src / MakerNote / XBM

Suggested apply order when taking the overlapping-file patches: 179 then 178 then 180 then 181. The others are independent.

Not posted (whole-tree vendor replacements, not a small plugin diff):

  • CVE-2024-28562/28563/28564/28569 bundled OpenEXR 2.2 Imf_2_2 — fixed in GitHub by OpenEXR 3.3.13 (#69) or -DUSE_SYSTEM_OPENEXR=ON
  • CVE-2024-28574/28575/28576 bundled OpenJPEG j2k.c — fixed in GitHub by OpenJPEG 2.5.4 (#68) or -DUSE_SYSTEM_LIBOPENJPEG=ON

Ticket #169 is an empty stub; use #170 for the ICO patch.