CVE-2021-44004: Medium severity siemens jt2go vulnerability
A vulnerability has been identified in JT2Go (All versions < V13.2.0.5), Teamcenter Visualization (All versions < V13.2.0.5). The TiffLoader.dll is vulnerable to an out of bounds read past the end of an allocated buffer when parsing TIFF files. An attacker could leverage this vulnerability to leak information in the context of the current process.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2021-44004.
Which software versions are affected by this vulnerability?
The vulnerability affects all versions of JT2Go and Teamcenter Visualization prior to V13.2.0.5.
What is the severity level of CVE-2021-44004?
CVE-2021-44004 has a severity level of medium.
What does this vulnerability allow an attacker to do?
This vulnerability allows an attacker to leak sensitive information by exploiting an out of bounds read past the end of an allocated buffer when parsing TIFF files.
Are there any fixes or patches available for this vulnerability?
Siemens has released a security advisory with recommended mitigations for this vulnerability. Please refer to the provided reference for more information.