top of page
perceptive_background_267k.jpg

FreeImage 3.18.0 contains a Use After Free in PluginTARGA.cpp;loadRLE().

Published:

13 January 2026 at 23:00:00

Alert date:

14 January 2026 at 18:00:46

Source:

nvd.nist.gov

Click to open the original link from this advisory

Supply Chain & Dependencies, Web Technologies

FreeImage version 3.18.0 contains a Use After Free vulnerability in the PluginTARGA.cpp file, specifically in the loadRLE() function. This memory corruption vulnerability could potentially allow attackers to execute arbitrary code or cause application crashes when processing malicious TARGA image files. The vulnerability has been documented with proof-of-concept code available on GitHub. Use After Free vulnerabilities are particularly dangerous as they can lead to remote code execution in applications that process untrusted image files. Organizations using FreeImage library should assess their exposure and consider updating or implementing mitigations.

Technical details

Mitigation steps:

Affected products:

FreeImage

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page