buildroot ▾
›
2025.02.x ▾
›
vulnerability
›
CVE-2021-40266
Component Overview
Vulnerability Overview
Name
CVE-2021-40266
Source
NVD (
link
)
Debian (
link
)
Description
FreeImage before 1.18.0, ReadPalette function in PluginTIFF.cpp is vulnerabile to null pointer dereference.
CWEs
CWE-476
Published Date
Aug 22, 2023
Updated Date
Jun 17, 2026
Workaround
-
Advisories
https://sourceforge.net/p/freeimage/bugs/334/
Exploit
https://sourceforge.net/p/freeimage/bugs/334/
Exploit
Analysis
#
Affected Component
Analysis
libfreeimage
Patched
Vulnerability Ratings
#
6.5
CVSSv31
NaN
other
Resolved with patches
#
libfreeimage (buildroot:2025.02.x)
#
Title
Author
Resolve
1
Patch #1
Thomas Perale <thomas.perale@mind.be>
CVE-2021-40266