NULL Pointer Dereference Vulnerability in FreeImage by FreeImage
CVE-2021-40264

6.5MEDIUM

Key Information:

Status
Vendor
CVE Published:
22 August 2023

What is CVE-2021-40264?

A NULL pointer dereference vulnerability exists in FreeImage prior to version 1.18.0, specifically within the FreeImage_CloneTag function located in FreeImageTag.cpp. This vulnerability may lead to application crashes and can be exploited to cause instability in software utilizing the FreeImage library. It is crucial for users and developers relying on FreeImage to update to the latest version to mitigate potential risks associated with this type of vulnerability.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.