PT-2022-15977 · Accusoft · Accusoft Imagegear
Published
2022-05-03
·
Updated
2022-05-10
·
CVE-2022-23400
CVSS v3.1
7.1
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Accusoft ImageGear version 19.10
Description
A stack-based buffer overflow vulnerability exists in the
IGXMPXMLParser::parseDelimiter functionality. A specially-crafted PSD file can overflow a stack buffer, potentially leading to denial of service or an information leak, depending on the application. An attacker can trigger this issue by providing a malicious file.Recommendations
For Accusoft ImageGear version 19.10, consider disabling the
IGXMPXMLParser::parseDelimiter functionality until a patch is available to prevent potential exploitation. Additionally, restrict the handling of PSD files from untrusted sources to minimize the risk of triggering this vulnerability. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Accusoft Imagegear