CVE-2021-28855

In Deark before 1.5.8, a specially crafted input file can cause a NULL pointer dereference in the dbuf_write function (src/deark-dbuf.c).
Configurations

Configuration 1 (hide)

cpe:2.3:a:entropymine:deark:*:*:*:*:*:*:*:*

History

26 Jan 2026, 17:16

Type Values Removed Values Added
References
  • () https://github.com/fuzzing2026/CVE-PoCs/tree/main/deark-CVE-2021-28855 -

21 Nov 2024, 06:00

Type Values Removed Values Added
References () https://fatihhcelik.github.io/posts/NULL-Pointer-Dereference-Deark/ - Patch, Third Party Advisory () https://fatihhcelik.github.io/posts/NULL-Pointer-Dereference-Deark/ - Patch, Third Party Advisory
References () https://github.com/jsummers/deark/commit/287f5ac31dfdc074669182f51ece637706070eeb - Patch, Third Party Advisory () https://github.com/jsummers/deark/commit/287f5ac31dfdc074669182f51ece637706070eeb - Patch, Third Party Advisory

Information

Published : 2021-04-14 17:15

Updated : 2026-01-26 17:16


NVD link : CVE-2021-28855

Mitre link : CVE-2021-28855

CVE.ORG link : CVE-2021-28855


JSON object : View

Products Affected

entropymine

  • deark
CWE
CWE-476

NULL Pointer Dereference