CVE-2021-33480
Linux Debian vulnerability analysis and mitigation

Overview

An use-after-free vulnerability was discovered in GOCR (GNU Optical Character Recognition) through version 0.53-20200802. The vulnerability specifically affects the context_correction() function in the pgm2asc.c file (CVE Details).

Technical details

The vulnerability is classified as a use-after-free issue (CWE-416) that occurs in the context_correction() function. The bug manifests in two specific locations within pgm2asc.c: at line 2857:51 and line 2817:39. When triggered, the vulnerability causes the program to attempt to read 4 bytes from previously freed memory regions (SourceForge Bug 40, SourceForge Bug 41).

Impact

The vulnerability affects the core functionality of GOCR, which is used for converting scanned images of text back to text files. While the immediate impact appears to be a crash in the CLI tool, the use-after-free condition could potentially lead to more severe consequences in certain contexts (Gentoo Advisory).

Exploitability

The vulnerability has been confirmed through proof-of-concept test cases that trigger the use-after-free condition. The issue can be reproduced using specific input files that trigger the vulnerable code paths in the context_correction() function (SourceForge Bug 40, SourceForge Bug 41).

Mitigation and workarounds

As of January 2024, some distributions like Gentoo have discontinued support for GOCR and recommend users uninstall the package using 'emerge --ask --depclean "app-text/gocr"'. No specific patches have been identified for this vulnerability (Gentoo Advisory).

Additional resources


SourceThis report was generated using AI

Related Linux Debian vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-42170HIGH7.8
  • Linux Debian logoLinux Debian
  • gimp-devel-tools
NoYesAug 08, 2026
CVE-2026-15534NONEN/A
  • Linux Debian logoLinux Debian
  • perl
NoNoAug 09, 2026
CVE-2026-17510NONEN/A
  • Linux Debian logoLinux Debian
  • libcrypt-openssl-pkcs12-perl
NoNoAug 09, 2026
CVE-2026-68082NONEN/A
  • Linux Debian logoLinux Debian
  • linux
NoYesAug 08, 2026
CVE-2026-68081NONEN/A
  • Linux Debian logoLinux Debian
  • linux
NoYesAug 08, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management