Heap Overflow Vulnerability in FreeImage by Open Source Developers
CVE-2021-40263

8.8HIGH

Key Information:

Status
Vendor
CVE Published:
22 August 2023

What is CVE-2021-40263?

A notable heap overflow vulnerability exists in FreeImage 1.18.0, specifically within the ofLoad function in PluginTIFF.cpp. This vulnerability poses significant risks as it can be exploited by attackers to execute arbitrary code or potentially crash the application, impacting the integrity of the software and the security of user data. Users of FreeImage are strongly encouraged to update to the latest version and implement best security practices to mitigate potential threats.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.