Datalogics APDFL library Heap-based Buffer Overflow
Published Oct 20, 2022
7.8
HIGHCVSS 3.1
EPSS 0.45%
Description
The APDFL.dll in Siemens JT2Go prior to V13.3.0.5 and Siemens Teamcenter Visualization prior to V14.0.0.2 contains an out of bounds write past the fixed-length heap-based buffer while parsing specially crafted PDF files. This could allow an attacker to execute code in the context of the current process.
Affected products
-
- Version unspecifiedStatusaffectedConstraints<V13.3.0.5
- Version
-
- Version unspecifiedStatusaffectedConstraints<V13.3.0.5
- Version
-
- Version unspecifiedStatusaffectedConstraints<V14.0.0.2
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Siemens | JT2Go | n/a |
| ||||||
| Siemens | Teamcenter Visualization V13.3 | n/a |
| ||||||
| Siemens | Teamcenter Visualization V14.0 | n/a |
|
- < 13.3.0.5
- ≥ 13.3.0 · < 13.3.0.5
- ≥ 14.0 · < 14.0.0.2
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Siemens recommends updating to the latest version: Teamcenter Visualization V13.3: Update to version 13.3.0.5 or later Teamcenter Visualization V14.0: Currently no fix available. JT2Go V13.3.0.5: Update to version 13.3.0.5 or later
For more information see Siemens Security Advisory SSA-829738
References (3)
- https://cert-portal.siemens.com/productcert/pdf/ssa-829738.pdf Vendor Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-34361 Advisory
- https://www.cisa.gov/uscert/ics/advisories/icsa-22-195-07 Third Party AdvisoryUS Government Resource
| Link | Providers | Tags |
|---|---|---|
| https://cert-portal.siemens.com/productcert/pdf/ssa-829738.pdf | Vendor Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-34361 | Advisory | |
| https://www.cisa.gov/uscert/ics/advisories/icsa-22-195-07 | Third Party AdvisoryUS Government Resource |
Change history (0)
No recorded changes yet.