Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6c7x-q2rf-g6cc

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.8

Описание

An exploitable integer underflow vulnerability exists in the CMP-parsing functionality of LEADTOOLS 20. A specially crafted CMP image file can cause an integer underflow, potentially resulting in code execution. An attacker can specially craft a CMP image to trigger this vulnerability.

An exploitable integer underflow vulnerability exists in the CMP-parsing functionality of LEADTOOLS 20. A specially crafted CMP image file can cause an integer underflow, potentially resulting in code execution. An attacker can specially craft a CMP image to trigger this vulnerability.

EPSS

Процентиль: 56%
0.00335
Низкий

7.8 High

CVSS3

Дефекты

CWE-190
CWE-191

Связанные уязвимости

CVSS3: 7.8
nvd
больше 6 лет назад

An exploitable integer underflow vulnerability exists in the CMP-parsing functionality of LEADTOOLS 20. A specially crafted CMP image file can cause an integer underflow, potentially resulting in code execution. An attacker can specially craft a CMP image to trigger this vulnerability.

EPSS

Процентиль: 56%
0.00335
Низкий

7.8 High

CVSS3

Дефекты

CWE-190
CWE-191