First published: Thu Dec 12 2019(Updated: )
An exploitable information disclosure vulnerability exists in the DICOM packet-parsing functionality of LEADTOOLS libltdic.so, version 20.0.2019.3.15. A specially crafted packet can cause an out-of-bounds read, resulting in information disclosure. An attacker can send a packet to trigger this vulnerability.
Credit: talos-cna@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Leadtools Leadtools | =20.0.2019.3.15 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2019-5090 is critical with a score of 7.5.
The affected software version of CVE-2019-5090 is Leadtools 20.0.2019.3.15.
The CWE ID of CVE-2019-5090 is 125.
An attacker can exploit CVE-2019-5090 by sending a specially crafted packet to trigger an out-of-bounds read, resulting in information disclosure.
You can find more information about CVE-2019-5090 at https://talosintelligence.com/vulnerability_reports/TALOS-2019-0882.