CVE-2023-35002: Buffer Overflow
Published Sep 25, 2023
·Updated
A heap-based buffer overflow vulnerability exists in the pictwread functionality of Accusoft ImageGear 20.1. A specially crafted malformed file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.
Affected Software
1 affected component
Accusoft ImageGear=20.1
Event History
Sep 25, 2023
CVE Published
via MITRE·03:22 PM
Data Sourced
via MITRE·03:22 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2023-35002.
2
What is the title of the vulnerability?
The title of the vulnerability is 'A heap-based buffer overflow vulnerability exists in the pictwread functionality of Accusoft ImageGear 20.1.'
3
What is the affected software?
The affected software is Accusoft ImageGear 20.1.
4
What is the severity of CVE-2023-35002?
The severity of CVE-2023-35002 is critical with a severity value of 9.8.
5
How can the vulnerability be exploited?
The vulnerability can be exploited by providing a specially crafted malformed file to trigger a heap-based buffer overflow, leading to arbitrary code execution.