CVE-2020-6094: Integer Overflow
Published May 6, 2020
·Updated
An exploitable code execution vulnerability exists in the TIFF fillinraster function of the igcore19d.dll library of Accusoft ImageGear 19.4, 19.5 and 19.6. A specially crafted TIFF file can cause an out-of-bounds write, resulting in remote code execution. An attacker can provide a malicious file to trigger this vulnerability.
Affected Software
3 affected components
Accusoft ImageGear=19.4.0
Accusoft ImageGear=19.5.0
Accusoft ImageGear=19.6.0
Event History
May 6, 2020
CVE Published
via MITRE·12:33 PM
Data Sourced
via MITRE·12:33 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2020-6094?
CVE-2020-6094 is a code execution vulnerability in the TIFF fillinraster function of the igcore19d.dll library of Accusoft ImageGear 19.4, 19.5, and 19.6.
2
How severe is CVE-2020-6094?
CVE-2020-6094 has a severity of 8.8 (Critical).
3
What is the affected software?
Accusoft ImageGear versions 19.4, 19.5, and 19.6 are affected.
4
How can CVE-2020-6094 be exploited?
A specially crafted TIFF file can cause an out-of-bounds write, resulting in remote code execution.
5
Are there any fixes or patches available?
No information on fixes or patches is currently available.