#VU34972 Integer overflow in LEADTOOLS - CVE-2019-5085
Published: December 12, 2019 / Updated: August 8, 2020
LEADTOOLS
LEAD Technologies, Inc.
Description
The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.
An exploitable code execution vulnerability exists in the DICOM packet-parsing functionality of LEADTOOLS libltdic.so, version 20.0.2019.3.15. A specially crafted packet can cause an integer overflow, resulting in heap corruption. An attacker can send a packet to trigger this vulnerability.