First published: Wed Feb 22 2023(Updated: )
Buffer Overflow vulnerability in Freeimage v3.18.0 allows attacker to cause a denial of service via a crafted JXR file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Freeimage Project Freeimage | =3.18.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-33367 is a buffer overflow vulnerability in Freeimage v3.18.0 that allows an attacker to cause a denial of service via a crafted JXR file.
The severity of CVE-2021-33367 is medium with a CVSS score of 5.5.
An attacker can exploit CVE-2021-33367 by sending a specially crafted JXR file to the vulnerable system, triggering a buffer overflow and causing a denial of service.
Yes, upgrading Freeimage to version 3.18.1 or later fixes the vulnerability.
CVE-2021-33367 is associated with CWE-119 (Improper Restriction of Operations within the Bounds of a Memory Buffer) and CWE-125 (Out-of-bounds Read).