CVE-2021-44007Off-by-one Error in Siemens Jt2go

CWE-193Off-by-one Error3 documents3 sources
Severity
5.5MEDIUMNVD
EPSS
0.2%
top 62.60%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 14
Latest updateDec 15

Description

A vulnerability has been identified in JT2Go (All versions < V13.2.0.5), Teamcenter Visualization (All versions < V13.2.0.5). The Tiff_Loader.dll contains an off-by-one error in the heap while parsing specially crafted TIFF files. This could allow an attacker to cause a denial-of-service condition.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages4 packages

CVEListV5siemens/teamcenter_visualizationAll versions < V13.2.0.5
NVDsiemens/jt2go< 13.2.0.5
CVEListV5siemens/jt2goAll versions < V13.2.0.5

Patches

🔴Vulnerability Details

2
GHSA
GHSA-cm9v-3mpg-x2w6: A vulnerability has been identified in JT2Go (All versions < V132021-12-15
CVEList
CVE-2021-44007: A vulnerability has been identified in JT2Go (All versions < V132021-12-14
CVE-2021-44007 — Off-by-one Error in Siemens Jt2go | cvebase