#VU34973 Out-of-bounds read in LEADTOOLS - CVE-2019-5090
Published: December 12, 2019 / Updated: August 8, 2020
LEADTOOLS
LEAD Technologies, Inc.
Description
The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.
An exploitable information disclosure vulnerability exists in the DICOM packet-parsing functionality of LEADTOOLS libltdic.so, version 20.0.2019.3.15. A specially crafted packet can cause an out-of-bounds read, resulting in information disclosure. An attacker can send a packet to trigger this vulnerability.