A vulnerability has been reported in AccuSoft ImageGear, which can be exploited by malicious people to compromise a vulnerable system.
The vulnerability is caused due to a boundary error within the igcore15d.dll component when processing CLP files and can be exploited to cause a stack-based buffer overflow via a specially crafted CLP file.
Successful exploitation allows execution of arbitrary code.
The vulnerability is confirmed in igcore15d.dll version 22.214.171.124 as well as version 126.96.36.199 included in the AccuSoft ImageGear version 15.2 installer. Other versions may also be affected. Also, any application using the vulnerable library may be vulnerable.
Solution: Do not open untrusted CLP files in applications using the affected library.
Provided and/or discovered by: Originally reported in Corel Paint Shop Pro Photo by:
Do you have additional information related to this advisory?
Please provide information about patches, mitigating factors, new versions, exploits, faulty patches, links, and other relevant data by posting comments to this Advisory. You can also send this
information to email@example.com