Junglewise Threat Intelligence

CVE-2021-42521: PYSEC-2022-255 - There is a NULL pointer dereference vulnerability in VTK, and it lies in IO/Infovis/vtkXMLTreeReader.cxx. The vendor didn't check the return

CVE-2021-42521 · Severity: low · CVSS 3.1 · Published 2022-08-25

Technologies: vtk (PyPI). Vendors: PyPI.

Executive brief

There is a NULL pointer dereference vulnerability in VTK, and it lies in IO/Infovis/vtkXMLTreeReader.cxx. The vendor didn't check the return value of libxml2 API 'xmlDocGetRootElement', and try to dereference it. It is unsafe as the return value can be NULL and that NULL pointer dereference may crash the application.

Affected products

  • PyPI vtk

Related threats