#VU46279 Type conversion in ImageGear - CVE-2020-6151
Published: September 4, 2020 / Updated: March 2, 2021
ImageGear
Accusoft Corporation
Description
The vulnerability allows a remote attacker to execute arbitrary code on the system.
The vulnerability exists due to a memory corruption in the TIFF "handle_COMPRESSION_PACKBITS" functionality. A remote attacker can use a specially crafted file, trigger memory corruption and execute arbitrary code on the target system.