CVE-2021-21949: Out-of-bounds Read
Published Apr 14, 2022
·Updated
An improper array index validation vulnerability exists in the JPEG-JFIF Scan header parser functionality of Accusoft ImageGear 19.10. A specially-crafted file can lead to an out-of-bounds write and potential code exectuion. An attacker can provide a malicious file to trigger this vulnerability.
Affected Software
1 affected component
Accusoft ImageGear=19.10
Event History
Apr 14, 2022
CVE Published
via MITRE·07:56 PM
Data Sourced
via MITRE·07:56 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this JPEG-JFIF Scan header parser vulnerability?
The vulnerability ID is CVE-2021-21949.
2
What is the severity of CVE-2021-21949?
The severity of CVE-2021-21949 is critical with a CVSS score of 8.8.
3
How does the vulnerability in Accusoft ImageGear 19.10 manifest?
The vulnerability in Accusoft ImageGear 19.10 is an improper array index validation vulnerability in the JPEG-JFIF Scan header parser functionality.
4
What is the potential impact of this vulnerability?
A specially-crafted file can lead to an out-of-bounds write and potential code execution.
5
How can an attacker exploit CVE-2021-21949?
An attacker can provide a malicious file to trigger the vulnerability.