CVE-2023-32653: Integer Underflow
An out-of-bounds write vulnerability exists in the dcmpixeldatadecode functionality of Accusoft ImageGear 20.1. A specially crafted malformed file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2023-32653.
What is the severity of CVE-2023-32653?
The severity of CVE-2023-32653 is critical with a CVSS score of 8.8.
How does the vulnerability in Accusoft ImageGear 20.1 occur?
The vulnerability occurs due to an out-of-bounds write in the dcm_pixel_data_decode functionality of Accusoft ImageGear 20.1.
How can the vulnerability be exploited?
The vulnerability can be exploited by an attacker who creates a specially crafted malformed file and tricks a victim into opening it, leading to arbitrary code execution.
Is there a fix or patch available for CVE-2023-32653?
As of now, there is no information available regarding a fix or patch for CVE-2023-32653. It is recommended to follow the security advisories and updates from Accusoft or the relevant vendor.