CVE-2023-1709
published 2023-06-07CVE-2023-1709: Datalogics Library APDFLThe v18.0.4PlusP1e and prior contains a stack-based buffer overflow due to documents containing corrupted fonts, which could allow an…
PriorityP337high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
0.26%
17.5th percentile
Datalogics Library APDFLThe v18.0.4PlusP1e and prior contains a stack-based buffer overflow due to documents containing corrupted fonts, which could allow an attack that causes an unhandled crash during the rendering process.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| datalogics | library_apdfl | <= v18.0.4PlusP1e | — |
| siemens | jt2go | < 14.2.0.2 | 14.2.0.2 |
| siemens | teamcenter_visualization | >= 13.2 < 13.2.0.13 | 13.2.0.13 |
| siemens | teamcenter_visualization | >= 13.2.0 < 13.2.0.13 | 13.2.0.13 |
| siemens | teamcenter_visualization | >= 13.3 < 13.3.0.9 | 13.3.0.9 |
| siemens | teamcenter_visualization | >= 13.3.0 < 13.3.0.9 | 13.3.0.9 |
| siemens | teamcenter_visualization | >= 14.0 < 14.0.0.5 | 14.0.0.5 |
| siemens | teamcenter_visualization | >= 14.1 < 14.1.0.7 | 14.1.0.7 |
| siemens | teamcenter_visualization | >= 14.2 < 14.2.0.2 | 14.2.0.2 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-hfx6-59cf-wmqp: The APDFL
ghsa_unreviewed·2023-06-07
CVE-2023-1709 [HIGH] CWE-121 GHSA-hfx6-59cf-wmqp: The APDFL
The APDFL.dll contains a memory corruption vulnerability while parsing
specially crafted PDF files. This could allow an attacker to execute
code in the context of the current process.
CISA ICS
Datalogics Library Third-Party
cisa_ics·2023-06-13·CVSS 7.8
[HIGH] Datalogics Library Third-Party
ICS Advisory
##
Datalogics Library Third-Party
Release DateJune 13, 2023
Alert CodeICSA-23-164-01
## 1. EXECUTIVE SUMMARY
- CVSS v3 5.5
- ATTENTION: Low attack complexity
- Vendor: Datalogics
- Equipment: Library APDFL v18.0.4PlusP1e
- Vulnerability: Stack-based buffer overflow
## 2. RISK EVALUATION
Successful exploitation of this vulnerability could allow an attacker to crash the device.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
The following Datalogics library versions are affected:
- Library APDFL v18.0.4PlusP1e and prior
## 3.2 VULNERABILITY OVERVIEW
3.2.1 STACK-BASED BUFFER OVERFLOW CWE-121
The affected product has a stack-based buffer overflow due to documents containing corrupted fonts, which could allow an attack that causes an unhandl
CISA ICS
Siemens Teamcenter Visualization and JT2Go
cisa_ics·2023-04-13·CVSS 7.8
[HIGH] Siemens Teamcenter Visualization and JT2Go
ICS Advisory
##
Siemens Teamcenter Visualization and JT2Go
Release DateApril 13, 2023
Alert CodeICSA-23-103-11
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
## 1. EXECUTIVE SUMMARY
- CVSS v3 7.8
- ATTENTION: Low attack complexity
- Vendor: Siemens
- Equipment: Teamcenter Visualization and JT2Go
- Vulnerability: Stack-based Buffer Overflow
## 2. RISK EVALUATION
Successful exploitation of this vulnerability could lead the application to crash or potentially lead to arbitrary code execution.
##
No detection rules found.
No public exploits indexed.
https://cert-portal.siemens.com/productcert/html/ssa-629917.htmlhttps://www.cisa.gov/news-events/ics-advisories/icsa-23-103-11https://www.cisa.gov/news-events/ics-advisories/icsa-23-164-01https://cert-portal.siemens.com/productcert/html/ssa-629917.htmlhttps://www.cisa.gov/news-events/ics-advisories/icsa-23-103-11https://www.cisa.gov/news-events/ics-advisories/icsa-23-164-01
2023-06-07
Published