CVE-2021-44007: Medium severity siemens jt2go vulnerability
Published Dec 14, 2021
·Updated
A vulnerability has been identified in JT2Go (All versions < V13.2.0.5), Teamcenter Visualization (All versions < V13.2.0.5). The TiffLoader.dll contains an off-by-one error in the heap while parsing specially crafted TIFF files. This could allow an attacker to cause a denial-of-service condition.
Affected Software
4 affected componentsFixes available
Siemens JT2Go<13.2.0.5
Siemens Teamcenter Visualization<13.2.0.5
Siemens JT2Go<13.2.0.5
13.2.0.5
Siemens Teamcenter Visualization<13.2.0.5
13.2.0.5
Remediation
Event History
Dec 14, 2021
CVE Published
via MITRE·12:06 PM
Data Sourced
via MITRE·12:06 PM
DescriptionWeakness
Data Sourced
via NVD·12:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2021-44007.
2
What software versions are affected by this vulnerability?
All versions of JT2Go and Teamcenter Visualization prior to V13.2.0.5 are affected.
3
What is the severity of CVE-2021-44007?
The severity of CVE-2021-44007 is medium, with a severity value of 5.5.
4
How does CVE-2021-44007 impact the affected software?
CVE-2021-44007 can cause a denial-of-service condition in the affected software.
5
Is there a fix available for this vulnerability?
Yes, upgrading to version V13.2.0.5 or later of JT2Go and Teamcenter Visualization will fix this vulnerability.