CVE-2021-42521
Last modified
CVE-2021-42521 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. There is a NULL pointer dereference vulnerability in VTK before 9.2.5, and it lies in IO/Infovis/vtkXMLTreeReader.cxx. The vendor didn't check the return value of libxml2 API 'xmlDocGetRootElement', and try to dereference it. EPSS estimates a 1.07% chance of exploitation in the next 30 days.
Description
There is a NULL pointer dereference vulnerability in VTK before 9.2.5, and it lies in IO/Infovis/vtkXMLTreeReader.cxx. The vendor didn't check the return value of libxml2 API 'xmlDocGetRootElement', and try to dereference it. It is unsafe as the return value can be NULL and that NULL pointer dereference may crash the application.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Vtk | Vtk | <= 9.0.0 |
References
- https://gitlab.kitware.com/vtk/vtk/issues/17818Exploit, Issue Tracking, Third Party Advisory
- https://gitlab.kitware.com/vtk/vtk/issues/17818Exploit, Issue Tracking, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-42521?
How severe is CVE-2021-42521?
How do I fix CVE-2021-42521?
Are you affected by CVE-2021-42521?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
