The APDFL.dll contains an out-of-bounds write past the fixed-length
Published Jan 13, 2023
7.8
HIGHCVSS 3.1
EPSS 0.44%
Description
The APDFL.dll contains an out-of-bounds write past the fixed-length heap-based buffer while parsing specially crafted PDF files. This could allow an attacker to execute code in the context of the current process.
Affected products
-
Affected
- ≥ 0, < 14.1.0.5
-
Affected
- ≥ 0, < 13.3.0.8
-
Affected
- ≥ 0, < 14.0.0.4
-
Affected
- ≥ 0, < 14.1.0.5
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Siemens | JT2Go | unaffected | Affected
|
| Siemens | Teamcenter Visualization V13.3 | unaffected | Affected
|
| Siemens | Teamcenter Visualization V14.0 | unaffected | Affected
|
| Siemens | Teamcenter Visualization V14.1 | unaffected | Affected
|
- < 14.1.0.5
- ≥ 13.3.0 · < 13.3.0.8
- ≥ 14.0 · < 14.0.0.4
- ≥ 14.1 · < 14.1.0.5
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Siemens released updates for the affected products and recommends updating to the latest versions: * JT2Go: Update to V14.1.0.5 or later version https://www.plm.automation.siemens.com/global/en/products/plm-components/jt2go.html .
* Teamcenter Visualization V13.3: Update to V13.3.0.8 or later version https://support.sw.siemens.com/ .
* Teamcenter Visualization V14.0: Update to V14.0.0.4 or later version https://support.sw.siemens.com/ .
* Teamcenter Visualization V14.1: Update to V14.1.0.5 or later version https://support.sw.siemens.com/ .
References (4)
- https://cert-portal.siemens.com/productcert/csaf/ssa-360681.json Third Party Advisory
- https://cert-portal.siemens.com/productcert/html/ssa-360681.html Third Party Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-42584 Advisory
- https://www.cisa.gov/uscert/ics/advisories/icsa-22-349-15 Third Party AdvisoryUS Government Resource
| Link | Providers | Tags |
|---|---|---|
| https://cert-portal.siemens.com/productcert/csaf/ssa-360681.json | Third Party Advisory | |
| https://cert-portal.siemens.com/productcert/html/ssa-360681.html | Third Party Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-42584 | Advisory | |
| https://www.cisa.gov/uscert/ics/advisories/icsa-22-349-15 | Third Party AdvisoryUS Government Resource |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
Red Hat
No data
GitHub
No data