CVE-2020-6075: Critical severity accusoft imagegear vulnerability
An exploitable out-of-bounds write vulnerability exists in the storedatabuffer function of the igcore19d.dll library of Accusoft ImageGear 19.5.0. A specially crafted PNG file can cause an out-of-bounds write, resulting in a remote code execution. An attacker needs to provide a malformed file to the victim to trigger the vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-6075?
The severity of CVE-2020-6075 is critical.
How does CVE-2020-6075 affect Accusoft ImageGear 19.5.0?
CVE-2020-6075 affects Accusoft ImageGear 19.5.0 by allowing remote code execution through a specially crafted PNG file.
What is the CWE ID for CVE-2020-6075?
The CWE ID for CVE-2020-6075 is CWE-787.
Are there any references for CVE-2020-6075?
Yes, you can find references for CVE-2020-6075 at https://talosintelligence.com/vulnerability_reports/TALOS-2020-0998.
How can CVE-2020-6075 be fixed?
To fix CVE-2020-6075, it is recommended to update Accusoft ImageGear to a version that includes the security patch.