Applies to FreeImage SVN trunk r1911 (also 3.19.0 [r1909]).
One patch covering the issue #35 metadata/RAS/XPM group (GitHub PR #96 / commit d474400):
NVD:
https://nvd.nist.gov/vuln/detail/CVE-2024-28568
https://nvd.nist.gov/vuln/detail/CVE-2024-9029
https://nvd.nist.gov/vuln/detail/CVE-2024-28570
https://nvd.nist.gov/vuln/detail/CVE-2024-28573
https://nvd.nist.gov/vuln/detail/CVE-2024-28577
https://nvd.nist.gov/vuln/detail/CVE-2024-28578
https://nvd.nist.gov/vuln/detail/CVE-2024-28580
GitHub: https://github.com/danoli3/FreeImage/commit/d474400 (PR https://github.com/danoli3/FreeImage/pull/96)
Apply from the FreeImage tree root (after CVE-2021-33367.patch if you take that too):
patch -p0 < CVE-2024-28568.patch
Anonymous