PT-2021-14769 · Accusoft · Accusoft Imagegear
Emmanuel Tacheau
·
Published
2021-04-13
·
Updated
2022-09-30
·
CVE-2021-21784
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Accusoft ImageGear version 19.8
Description
An out-of-bounds write issue exists in the JPG format SOF marker processing. A specially crafted malformed file can lead to memory corruption. An attacker can provide a malicious file to trigger this issue.
Recommendations
For Accusoft ImageGear version 19.8, avoid processing untrusted or malicious JPG files until a patch is available. As a temporary workaround, consider validating all input files to prevent memory corruption.
Exploit
Fix
Buffer Overflow
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Accusoft Imagegear