CVE-2020-26985: Siemens JT2Go RGB and SGI File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
A vulnerability has been identified in JT2Go (All versions < V13.1.0), Teamcenter Visualization (All versions < V13.1.0). Affected applications lack proper validation of user-supplied data when parsing of RGB and SGI files. This could result in a heap-based buffer overflow. An attacker could leverage this vulnerability to execute code in the context of the current process. (ZDI-CAN-11986, ZDI-CAN-11994)
Other sources
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Siemens JT2Go. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of RGB and SGI files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.
— ZDI
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-26985?
CVE-2020-26985 is classified as a vulnerability that could lead to a heap-based buffer overflow, which may allow attackers to execute arbitrary code.
How do I fix CVE-2020-26985?
To mitigate CVE-2020-26985, users should update to versions 13.1.0 or higher of JT2Go and Teamcenter Visualization.
What versions are affected by CVE-2020-26985?
CVE-2020-26985 affects all versions of JT2Go and Teamcenter Visualization prior to version 13.1.0.
What type of vulnerability is CVE-2020-26985?
CVE-2020-26985 is a buffer overflow vulnerability due to improper validation of user-supplied data when parsing RGB and SGI files.
Can CVE-2020-26985 lead to remote code execution?
Yes, if exploited, CVE-2020-26985 could allow remote attackers to execute arbitrary code on the affected systems.