PT-2022-12686 · Unknown · Iipimage High Resolution Streaming Image Server
Published
2022-02-07
·
Updated
2022-02-11
·
CVE-2021-46389
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
IIPImage High Resolution Streaming Image Server versions prior to commit 882925b295a80ec992063deffc2a3b0d803c3195
Description
The issue is caused by an integer overflow in
iipsrv.fcgi through malformed HTTP query parameters. This can be exploited by sending specifically crafted requests to the server.Recommendations
For versions prior to commit 882925b295a80ec992063deffc2a3b0d803c3195, update to a version that includes the fix for the integer overflow in
iipsrv.fcgi. As a temporary workaround, consider restricting access to the iipsrv.fcgi module to minimize the risk of exploitation.Fix
Integer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Iipimage High Resolution Streaming Image Server