CVE-2021-44436: Medium severity siemens jt open vulnerability
A vulnerability has been identified in JT Utilities (All versions < V13.1.1.0), JTTK (All versions < V11.1.1.0). JTTK library in affected products is vulnerable to an out of bounds read past the end of an allocated buffer when parsing specially crafted JT files. An attacker could leverage this vulnerability to leak information in the context of the current process. (ZDI-CAN-14905)
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-44436.
What is the severity of CVE-2021-44436?
The severity of CVE-2021-44436 is medium with a CVSS score of 3.3.
Which software versions are affected by CVE-2021-44436?
JT Utilities versions earlier than V13.1.1.0 and JTTK versions earlier than V11.1.1.0 are affected by CVE-2021-44436.
What is the vulnerability type of CVE-2021-44436?
The vulnerability type of CVE-2021-44436 is out-of-bounds read.
How can an attacker exploit CVE-2021-44436?
An attacker can exploit CVE-2021-44436 by leveraging the vulnerability to perform an out of bounds read when parsing specially crafted JT files.