#VU50570 Write-what-where Condition in ImageGear - CVE-2020-13572
Published: February 10, 2021 / Updated: March 2, 2021
ImageGear
Accusoft Corporation
Description
The vulnerability allows a remote attacker to execute arbitrary code on the system.
The vulnerability exists due to a write-what-where condition in the way the GIF parser decodes LZW compressed streams. A remote attacker can use a specially crafted file, trigger a heap overflow and execute arbitrary code on the target system.