CVE-2021-40266 — NULL Pointer Dereference in Project Freeimage

Severity
6.5MEDIUMNVD
EPSS
0.1%
top 75.64%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 22

Description

FreeImage before 1.18.0, ReadPalette function in PluginTIFF.cpp is vulnerabile to null pointer dereference.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6

Affected Packages1 packages

â–¶NVDfreeimage_project/freeimage< 1.18.0

🔴Vulnerability Details

3
OSV
CVE-2021-40266: FreeImage before 1↗2023-08-22
â–¶
CVEList
CVE-2021-40266: FreeImage before 1↗2023-08-22
â–¶
GHSA
GHSA-843v-g785-48r2: FreeImage before 1↗2023-08-22
â–¶

📋Vendor Advisories

1
Debian
CVE-2021-40266: freeimage - FreeImage before 1.18.0, ReadPalette function in PluginTIFF.cpp is vulnerabile t...↗2021
â–¶
CVE-2021-40266 — NULL Pointer Dereference | cvebase