CVE-2020-6094
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
An exploitable code execution vulnerability exists in the TIFF fillinraster function of the igcore19d.dll library of Accusoft ImageGear 19.4, 19.5 and 19.6. A specially crafted TIFF file can cause an out-of-bounds write, resulting in remote code execution. An attacker can provide a malicious file to trigger this vulnerability.
Se presenta una vulnerabilidad de ejecución de código explotable en la función TIFF fillinraster de la biblioteca igcore19d.dll de Accusoft ImageGear versiones 19.4, 19.5 y 19.6. Un archivo TIFF especialmente diseñado puede causar una escritura fuera de límites, resultando en una ejecución de código remota. Un atacante puede proporcionar un archivo malicioso para desencadenar esta vulnerabilidad.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-01-07 CVE Reserved
- 2020-05-06 CVE Published
- 2024-06-15 EPSS Updated
- 2024-08-04 CVE Updated
- 2024-08-04 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-190: Integer Overflow or Wraparound
- CWE-787: Out-of-bounds Write
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://talosintelligence.com/vulnerability_reports/TALOS-2020-1017 | 2024-08-04 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Accusoft Search vendor "Accusoft" | Imagegear Search vendor "Accusoft" for product "Imagegear" | 19.4.0 Search vendor "Accusoft" for product "Imagegear" and version "19.4.0" | - |
Affected
| ||||||
Accusoft Search vendor "Accusoft" | Imagegear Search vendor "Accusoft" for product "Imagegear" | 19.5.0 Search vendor "Accusoft" for product "Imagegear" and version "19.5.0" | - |
Affected
| ||||||
Accusoft Search vendor "Accusoft" | Imagegear Search vendor "Accusoft" for product "Imagegear" | 19.6.0 Search vendor "Accusoft" for product "Imagegear" and version "19.6.0" | - |
Affected
|