Heap Overflow Vulnerability in FreeImage Library by FreeImage Developers
CVE-2021-40265

8.8HIGH

Key Information:

Status
Vendor
CVE Published:
22 August 2023

What is CVE-2021-40265?

A heap overflow bug has been identified in the FreeImage library prior to version 1.18.0, specifically in the ofLoad function found in PluginJPEG.cpp. This vulnerability can arise when processing JPEG files, potentially leading to memory corruption and other serious exploits. Users of this library should take precautions, as unpatched versions may be susceptible to attacks that could compromise system integrity or data security.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.