CVE-2023-39453: Use After Free
Published Sep 25, 2023
·Updated
A use-after-free vulnerability exists in the tifparsesubIFD functionality of Accusoft ImageGear 20.1. A specially crafted malformed file can lead to arbitrary code execution. An attacker can deliver this file to trigger this vulnerability.
Affected Software
1 affected component
Accusoft ImageGear=20.1
Event History
Sep 25, 2023
CVE Published
via MITRE·03:22 PM
Data Sourced
via MITRE·03:22 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2023-39453?
CVE-2023-39453 is a use-after-free vulnerability in the tif_parse_sub_IFD functionality of Accusoft ImageGear 20.1.
2
How severe is CVE-2023-39453?
CVE-2023-39453 has a severity rating of 9.8 (Critical).
3
How does CVE-2023-39453 affect Accusoft ImageGear?
CVE-2023-39453 affects Accusoft ImageGear version 20.1.
4
What is the risk of CVE-2023-39453?
CVE-2023-39453 allows an attacker to execute arbitrary code by delivering a specially crafted malformed file.
5
Is there a fix for CVE-2023-39453?
There is no available fix for CVE-2023-39453 at the moment. It is recommended to follow the vendor's security advisory for updates.