PT-2022-9207 · Accusoft · Accusoft Imagegear

·

CVE-2021-21944

·

Published

2022-04-14

·

Updated

2022-12-06

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Accusoft ImageGear version 19.10
Description A heap-based buffer overflow issue exists in the TIFF parser functionality. This can be triggered by a specially-crafted file, leading to a heap buffer overflow. An attacker can exploit this by providing a malicious file. The issue occurs when trying to copy the first 12 bits from a local variable.
Recommendations For Accusoft ImageGear version 19.10, consider avoiding the use of the TIFF parser functionality until a fix is available. As a temporary workaround, restrict the handling of specially-crafted files to minimize the risk of exploitation.

Exploit

Fix

Memory Corruption

Heap Based Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-21944

Affected Products

Accusoft Imagegear