NewsSecurity Vulnerabilities

Accusoft ImageGear parse_raster_data out-of-bounds write vulnerability [CVE-2021-40398]

CVE number = CVE-2021-40398

The ImageGear library is a document-imaging developer toolkit that offers image conversion, creation, editing, annotation and more. It supports more than 100 formats such as DICOM, PDF, Microsoft Office and others.

An out-of-bounds write vulnerability exists in the parse_raster_data functionality of Accusoft ImageGear 19.10.

A specially-crafted malformed file can lead to memory corruption.

An attacker can provide a malicious file to trigger this vulnerability.

Tested Versions

Accusoft ImageGear 19.10

Luke Simmonds

Blogger at www.systemtek.co.uk

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.