PT-2023-5556 · Accusoft · Accusoft Imagegear
Emmanuel Tacheau
·
Published
2023-05-12
·
Updated
2023-09-26
·
CVE-2023-32614
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Accusoft ImageGear version 20.1
Description
A heap-based buffer overflow vulnerability exists in the
create png object() functionality. This issue is related to a buffer overflow, which can be triggered by a specially crafted malicious PNG file, potentially leading to memory corruption. An attacker can exploit this vulnerability by providing a malicious file, affecting the confidentiality, integrity, and availability of protected information.Recommendations
For Accusoft ImageGear version 20.1, consider disabling the
create png object() function until a patch is available to prevent potential exploitation. Restrict the handling of PNG files from untrusted sources to minimize the risk of triggering this vulnerability.Exploit
Fix
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Accusoft Imagegear