PT-2021-14803 · Accusoft · Accusoft Imagegear

Emmanuel Tacheau

·

Published

2021-06-11

·

Updated

2022-08-24

·

CVE-2021-21833

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Accusoft ImageGear version 19.9
Description An issue exists in the TIF IP planar raster unpack functionality where improper array index validation can occur. This can be triggered by a specially crafted malformed file, leading to an out-of-bounds write. An attacker can exploit this by providing a malicious file.
Recommendations For Accusoft ImageGear version 19.9, consider avoiding the use of the TIF IP planar raster unpack functionality until a fix is available. As a temporary workaround, restrict the processing of untrusted or malicious files to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Validation of Array Index

Buffer Overflow

Weakness Enumeration

Related Identifiers

CVE-2021-21833

Affected Products

Accusoft Imagegear