PT-2020-2720 · Accusoft · Imagegear
Published
2020-01-30
·
Updated
2022-07-28
·
CVE-2020-6076
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Accusoft ImageGear version 19.5.0
Description
The issue is related to an out-of-bounds write vulnerability in the igcore19d.dll ICO icoread parser of the ImageGear library. This vulnerability can be exploited by a remote attacker using a specially crafted ICO file, potentially leading to remote code execution. The attacker needs to provide a malformed file to the victim to trigger the issue.
Recommendations
For Accusoft ImageGear version 19.5.0, consider avoiding the use of the
IG load file function or restricting access to the ICO file parsing functionality until a patch is available. As a temporary workaround, refrain from processing untrusted or specially crafted ICO files to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Imagegear