Stack Exhaustion Vulnerability in FreeImage by FreeImage Team
CVE-2021-40262

6.5MEDIUM

Key Information:

Status
Vendor
CVE Published:
22 August 2023

What is CVE-2021-40262?

A stack exhaustion issue was identified in FreeImage versions prior to 1.18.0, specifically within the Validate function located in PluginRAW.cpp. This vulnerability has the potential to be exploited through recursive calls that consume excessive stack space, leading to application instability and potential service interruptions.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.