QID 995537

Date Published: 2023-10-09

QID 995537: DotNet (Nuget) Security Update for ImageResizer.Plugins.FreeImage (GHSA-wqcr-xm43-hpqr)

This vulnerability affects deployments of FreeImage that involve decoding or processing malicious source .webp files. If you only process your own trusted files, this should not affect you, but you should remove FreeImage from your project, as it is not maintained and presents a massive security risk.

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as Medium - 5.4 severity.
  • Solution
    Refer to Github security advisory GHSA-wqcr-xm43-hpqr for updates and patch information.
    Vendor References

    CVEs related to QID 995537

    Software Advisories
    Advisory ID Software Component Link