PT-2023-5556 · Accusoft · Accusoft Imagegear

Emmanuel Tacheau

·

Published

2023-05-12

·

Updated

2023-09-26

·

CVE-2023-32614

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Accusoft ImageGear version 20.1
Description A heap-based buffer overflow vulnerability exists in the create png object() functionality. This issue is related to a buffer overflow, which can be triggered by a specially crafted malicious PNG file, potentially leading to memory corruption. An attacker can exploit this vulnerability by providing a malicious file, affecting the confidentiality, integrity, and availability of protected information.
Recommendations For Accusoft ImageGear version 20.1, consider disabling the create png object() function until a patch is available to prevent potential exploitation. Restrict the handling of PNG files from untrusted sources to minimize the risk of triggering this vulnerability.

Exploit

Fix

Memory Corruption

Weakness Enumeration

Related Identifiers

BDU:2023-06207
CVE-2023-32614

Affected Products

Accusoft Imagegear