First published: Tue Jul 13 2021(Updated: )
A vulnerability has been identified in JT2Go (All versions < V13.2), Teamcenter Visualization (All versions < V13.2). The BMP_Loader.dll library in affected applications lacks proper validation of user-supplied data when parsing BMP files. A malformed input file could result in an infinite loop condition that leads to denial of service condition. An attacker could leverage this vulnerability to consume excessive resources. (CNVD-C-2021-79300)
Credit: productcert@siemens.com
Affected Software | Affected Version | How to fix |
---|---|---|
Siemens JT2Go | <13.2.0 | |
Siemens Teamcenter Visualization | <13.2.0 | |
Siemens JT2Go | <13.2 | 13.2 |
Siemens Teamcenter Visualization | <13.2 | 13.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-34332 affects all versions of JT2Go and Teamcenter Visualization prior to version 13.2.
CVE-2021-34332 involves improper validation of user-supplied data in the BMP_Loader.dll library, leading to potential infinite loops when handling malformed BMP files.
To mitigate CVE-2021-34332, update JT2Go and Teamcenter Visualization to version 13.2 or later.
The vulnerability could cause an infinite loop, potentially leading to denial of service in affected applications.
The vendor for the affected products is Siemens.