Back

HIGH

Datalogics APDFL library Heap-based Buffer Overflow

Published Oct 20, 2022

Description

The APDFL.dll in Siemens JT2Go prior to V13.3.0.5 and Siemens Teamcenter Visualization prior to V14.0.0.2 contains an out of bounds write past the fixed-length heap-based buffer while parsing specially crafted PDF files. This could allow an attacker to execute code in the context of the current process.

Affected products

Remediation

Vendor solution

Siemens recommends updating to the latest version: Teamcenter Visualization V13.3: Update to version 13.3.0.5 or later Teamcenter Visualization V14.0: Currently no fix available. JT2Go V13.3.0.5: Update to version 13.3.0.5 or later

For more information see Siemens Security Advisory SSA-829738

References (3)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner icscert
Published Oct 20, 2022
Updated Apr 16, 2025
Reserved Jun 13, 2022
CISA Vulnrichment
Updated Apr 16, 2025
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner icscert
Published Oct 20, 2022
Updated Apr 16, 2025
Exploited since n/a
EUVD-2022-34361