CVE-2021-40145
HIGHLibgd < 2.3.2 - Double Free
Title source: ruleDescription
gdImageGd2Ptr in gd_gd2.c in the GD Graphics Library (aka LibGD) through 2.3.2 has a double free. NOTE: the vendor's position is "The GD2 image format is a proprietary image format of libgd. It has to be regarded as being obsolete, and should only be used for development and testing purposes.
References (3)
Scores
CVSS v3
7.5
EPSS
0.0054
EPSS Percentile
67.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Classification
CWE
CWE-415
Status
published
Affected Products (1)
libgd/libgd
< 2.3.2
Timeline
Published
Aug 26, 2021
Tracked Since
Feb 18, 2026