CVE-2023-1709: Datalogics Library APDFL Stack-based Buffer Overflow
Datalogics Library APDFLThe v18.0.4PlusP1e and prior contains a stack-based buffer overflow due to documents containing corrupted fonts, which could allow an attack that causes an unhandled crash during the rendering process.
Affected Software
Remediation
Information
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2023-1709?
CVE-2023-1709 is a vulnerability found in Datalogics Library APDFL versions v18.0.4PlusP1e and prior, which allows for a stack-based buffer overflow during the rendering process.
How does CVE-2023-1709 occur?
CVE-2023-1709 occurs when documents containing corrupted fonts are processed by Datalogics Library APDFL, leading to a stack-based buffer overflow vulnerability.
What is the severity level of CVE-2023-1709?
The severity level of CVE-2023-1709 is rated as high, with a CVSS score of 7.8.
Which software versions are affected by CVE-2023-1709?
Siemens JT2Go versions up to 14.2.0.2 and Siemens Teamcenter Visualization versions 13.2.0.13 to 14.2.0.2 are affected by CVE-2023-1709.
How can I mitigate CVE-2023-1709?
To mitigate CVE-2023-1709, it is recommended to update to a patched version of Datalogics Library APDFL that addresses the stack-based buffer overflow vulnerability.