First published: Tue Aug 22 2023(Updated: )
FreeImage before 1.18.0, ReadPalette function in PluginTIFF.cpp is vulnerabile to null pointer dereference.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Freeimage Project Freeimage | <1.18.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-40266.
The affected software is FreeImage version up to exclusive 1.18.0.
The severity of CVE-2021-40266 is medium with a CVSS score of 6.5.
CVE-2021-40266 occurs due to a null pointer dereference vulnerability in the ReadPalette function in PluginTIFF.cpp.
Yes, FreeImage released a fix in version 1.18.0.