CVE-2021-33367: Buffer Overflow
Published Feb 22, 2023
·Updated
Buffer Overflow vulnerability in Freeimage v3.18.0 allows attacker to cause a denial of service via a crafted JXR file.
Affected Software
1 affected component
Freeimage Project Freeimage=3.18.0
Event History
Feb 22, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is CVE-2021-33367?
CVE-2021-33367 is a buffer overflow vulnerability in Freeimage v3.18.0 that allows an attacker to cause a denial of service via a crafted JXR file.
2
What is the severity of CVE-2021-33367?
The severity of CVE-2021-33367 is medium with a CVSS score of 5.5.
3
How can an attacker exploit CVE-2021-33367?
An attacker can exploit CVE-2021-33367 by sending a specially crafted JXR file to the vulnerable system, triggering a buffer overflow and causing a denial of service.
4
Is there a fix available for CVE-2021-33367?
Yes, upgrading Freeimage to version 3.18.1 or later fixes the vulnerability.
5
What CWE categories are associated with CVE-2021-33367?
CVE-2021-33367 is associated with CWE-119 (Improper Restriction of Operations within the Bounds of a Memory Buffer) and CWE-125 (Out-of-bounds Read).