PT-2019-17479 · Lead Technologies · Leadtools
Published
2019-11-06
·
Updated
2022-06-21
·
CVE-2019-5099
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
LEADTOOLS version 20
Description
An integer underflow vulnerability exists in the CMP-parsing functionality. A specially crafted CMP image file can cause an integer underflow, potentially resulting in code execution. An attacker can specially craft a CMP image to trigger this issue.
Recommendations
For LEADTOOLS version 20, consider avoiding the use of CMP image files until a patch or fix is available. As a temporary workaround, restrict the processing of CMP images to minimize the risk of exploitation.
Exploit
Fix
Integer Underflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Leadtools