LEADTOOLS 20 Out-of-bounds Write Vulnerability

Summary

An exploitable heap out-of-bounds write vulnerability exists in the TIF-parsing functionality of LEADTOOLS 20.

 

 

 

 

Credit:

The information has been provided by Marcin Towalski

The original article can be found at:https://talosintelligence.com/vulnerability_reports/TALOS-2019-0876


Details

A specially crafted TIF image can cause an offset beyond the bounds of a heap allocation to be written, potentially resulting in code execution. An attacker can specially craft a TIF image to trigger this vulnerability.

 

Vulnerable Systems:

LEADTOOLS 20

 

CVE Information:

CVE-2019-5084

Disclosure Timeline:
Published Date:11/6/2019