#VU23610 Integer underflow in Kakadu SDK - CVE-2019-5144
Published: December 16, 2019 / Updated: January 30, 2020
Kakadu SDK
Kakadu Software
Description
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to integer underflow in the "derive_taps_and_gains" function in "kdu_v7ar.dll". A remote attacker can send a specially crafted jp2 file, trigger integer underflow and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.