Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Thu, 11 Apr 2024 09:02:25 +0000
From: Michael Knap <>
To: "" <>
Cc: "" <>
Subject: Re: Re: CWE-121, CWE-122: libfreeimage 3.40-3.18/19+ buffer overflow

-------- Original Message --------
On 11/04/2024 09:22, Tianyu Chen wrote:

> Hi Michael,
> I believe there may be a duplicate report for freeimage that you should be aware of. You can find it at the following link:


> The linked report includes CVE-2024-28562, CVE-2024-28563, CVE-2024-28564, CVE-2024-28565, and more up to CVE-2024-28584.

> Best regards,
> Tianyu Chen

Hi Tianyu,

Indeed, it seems so! I apologize for any inconvenience this may have caused.

I conducted a search on MITRE for the library and found several current CVEs,
but I did not come across this specific report. Given that they are fairly recent,
there might have been a period during which they were not yet visible in public searches.

Thank you for bringing this to my attention!

Best regards, 

Michael Knap

Download attachment "signature.asc" of type "application/pgp-signature" (250 bytes)

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.