CVE-2021-40264: Null Pointer Dereference
Published Aug 22, 2023
·Updated
NULL pointer dereference vulnerability in FreeImage before 1.18.0 via the FreeImageCloneTag function inFreeImageTag.cpp.
Affected Software
1 affected component
Freeimage Project Freeimage<1.18.0
Event History
Aug 22, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is CVE-2021-40264?
CVE-2021-40264 is a NULL pointer dereference vulnerability in FreeImage before version 1.18.0.
2
How does CVE-2021-40264 impact FreeImage?
CVE-2021-40264 allows an attacker to cause a denial of service (application crash) by exploiting a NULL pointer dereference in the FreeImage_CloneTag function.
3
Which version of FreeImage is affected by CVE-2021-40264?
FreeImage versions up to (but excluding) 1.18.0 are affected by CVE-2021-40264.
4
What is the severity of CVE-2021-40264?
The severity of CVE-2021-40264 is medium, with a CVSSv3 base score of 6.5.
5
Is there a fix available for CVE-2021-40264?
Yes, the fix for CVE-2021-40264 is to update to FreeImage version 1.18.0 or later.