CVE-2021-40145: Double Free
Published Aug 26, 2021
·Updated
DISPUTED gdImageGd2Ptr in gdgd2.c in the GD Graphics Library (aka LibGD) through 2.3.2 has a double free. NOTE: the vendor's position is "The GD2 image format is a proprietary image format of libgd. It has to be regarded as being obsolete, and should only be used for development and testing purposes."
Affected Software
1 affected component
Libgd Libgd<=2.3.2
Remediation
Event History
Aug 26, 2021
CVE Published
via MITRE·12:34 AM
Data Sourced
via MITRE·12:34 AM
Description
Disputed
01:15 AM
Data Sourced
via NVD·01:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2021-40145?
CVE-2021-40145 is a vulnerability in the GD Graphics Library (LibGD) through version 2.3.2 that allows for a double free.
2
What is the severity of CVE-2021-40145?
CVE-2021-40145 has a severity of 7.5 (high).
3
How does CVE-2021-40145 affect software?
CVE-2021-40145 affects LibGD version 2.3.2.
4
Is there a fix for CVE-2021-40145?
Yes, a fix for CVE-2021-40145 is available.
5
Where can I find more information about CVE-2021-40145?
More information about CVE-2021-40145 can be found at the following references: [link1], [link2], [link3].