PT-2022-12686 · Unknown · Iipimage High Resolution Streaming Image Server

Published

2022-02-07

·

Updated

2022-02-11

·

CVE-2021-46389

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions IIPImage High Resolution Streaming Image Server versions prior to commit 882925b295a80ec992063deffc2a3b0d803c3195
Description The issue is caused by an integer overflow in iipsrv.fcgi through malformed HTTP query parameters. This can be exploited by sending specifically crafted requests to the server.
Recommendations For versions prior to commit 882925b295a80ec992063deffc2a3b0d803c3195, update to a version that includes the fix for the integer overflow in iipsrv.fcgi. As a temporary workaround, consider restricting access to the iipsrv.fcgi module to minimize the risk of exploitation.

Fix

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-46389

Affected Products

Iipimage High Resolution Streaming Image Server