CVE-2021-44003Use of Uninitialized Variable in Siemens Jt2go

Severity
5.5MEDIUMNVD
EPSS
0.2%
top 63.38%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 14
Latest updateDec 15

Description

A vulnerability has been identified in JT2Go (All versions < V13.2.0.5), Teamcenter Visualization (All versions < V13.2.0.5). The Tiff_Loader.dll is vulnerable to use of uninitialized memory while parsing user supplied TIFF files. This could allow an attacker to cause a denial-of-service condition.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages4 packages

CVEListV5siemens/teamcenter_visualizationAll versions < V13.2.0.5
NVDsiemens/jt2go< 13.2.0.5
CVEListV5siemens/jt2goAll versions < V13.2.0.5

Patches

🔴Vulnerability Details

2
GHSA
GHSA-365p-m6g8-hhgp: A vulnerability has been identified in JT2Go (All versions < V132021-12-15
CVEList
CVE-2021-44003: A vulnerability has been identified in JT2Go (All versions < V132021-12-14
CVE-2021-44003 — Use of Uninitialized Variable | cvebase