First published: Fri Jan 13 2023(Updated: )
The APDFL.dll contains a stack-based buffer overflow vulnerability that could be triggered while parsing specially crafted PDF files. This could allow an attacker to execute code in the context of the current process.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Siemens JT2Go | <14.1.0.5 | |
Siemens Teamcenter Visualization | >=13.3.0<13.3.0.8 | |
Siemens Teamcenter Visualization | >=14.0.0<14.0.0.4 | |
Siemens Teamcenter Visualization | >=14.1<14.1.0.5 | |
Siemens JT2Go: All versions prior to V14.1.0.5 | ||
Siemens Teamcenter Visualization V13.3: All versions prior to V13.3.0.8 | ||
Siemens Teamcenter Visualization V14.0: All versions prior to V14.0.0.4 | ||
Siemens Teamcenter Visualization V14.1: All versions prior to V14.1.0.5 |
Siemens released updates for the affected products and recommends updating to the latest versions: * JT2Go: Update to V14.1.0.5 or later version https://www.plm.automation.siemens.com/global/en/products/plm-components/jt2go.html . * Teamcenter Visualization V13.3: Update to V13.3.0.8 or later version https://support.sw.siemens.com/ . * Teamcenter Visualization V14.0: Update to V14.0.0.4 or later version https://support.sw.siemens.com/ . * Teamcenter Visualization V14.1: Update to V14.1.0.5 or later version https://support.sw.siemens.com/ .
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-3159 is a stack-based buffer overflow vulnerability in the APDFL.dll library that can be exploited by parsing specially crafted PDF files, potentially allowing an attacker to execute code in the context of the current process.
Siemens JT2Go versions up to and excluding 14.1.0.5 are affected by CVE-2022-3159.
Siemens Teamcenter Visualization versions from 13.3.0 to 13.3.0.8, from 14.0.0 to 14.0.0.4, and from 14.1 to 14.1.0.5 are affected by CVE-2022-3159.
CVE-2022-3159 has a severity rating of 7.8 (High).
You can find more information about CVE-2022-3159 on the Siemens CERT Portal website and the CISA website.