CVE-2021-44008: Medium severity siemens jt2go vulnerability
A vulnerability has been identified in JT2Go (All versions < V13.2.0.5), Teamcenter Visualization (All versions < V13.2.0.5). The TiffLoader.dll is vulnerable to an out of bounds read past the end of an allocated buffer when parsing TIFF files. An attacker could leverage this vulnerability to leak information in the context of the current process.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2021-44008?
The severity of CVE-2021-44008 is medium with a CVSS score of 5.5.
Which software versions are affected by CVE-2021-44008?
All versions of JT2Go and Teamcenter Visualization prior to V13.2.0.5 are affected by CVE-2021-44008.
What is the vulnerability description of CVE-2021-44008?
CVE-2021-44008 is a vulnerability in JT2Go and Teamcenter Visualization that allows an attacker to perform an out of bounds read when parsing TIFF files, potentially leading to information leakage.
How can an attacker exploit CVE-2021-44008?
An attacker can exploit CVE-2021-44008 by crafting a malicious TIFF file and tricking a user into opening it, which can lead to the attacker leaking sensitive information from the affected system.
Is there a fix available for CVE-2021-44008?
Yes, upgrading to version V13.2.0.5 or later of JT2Go and Teamcenter Visualization will fix the vulnerability CVE-2021-44008.