ZeroHour

CVE-2022-23400

PoC
CVSS 3.1
7.1 high
EPSS
<1%p54
Published
()
Modified
Description

A stack-based buffer overflow vulnerability exists in the IGXMPXMLParser::parseDelimiter functionality of Accusoft ImageGear 19.10. A specially-crafted PSD file can overflow a stack buffer, which could either lead to denial of service or, depending on the application, to an information leak. An attacker can provide a malicious file to trigger this vulnerability.

Vendors
accusoft
Products
imagegear
Weakness
CWE-193, CWE-787
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H

In the news