CVE-2019-5125 describes a heap overflow vulnerability in the JPEG2000 parsing functionality of LEADTOOLS 20. A specially crafted J2K image file can lead to an out-of-bounds write, potentially enabling remote code execution. This vulnerability has a CVSS score of 7.8 (High), indicating a local attack vector with low complexity, requiring user interaction, and leading to high impacts on confidentiality, integrity, and availability. While no public exploits like Metasploit or ExploitDB entries exist, and it's not in CISA's KEV catalog, there has been some community discussion and media coverage, suggesting awareness within the security community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 20.0.2019.11.19CPE matchmatch criteria | cpe:2.3:a:leadtools:leadtools:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.