ZDI-21-233: Siemens JT2Go HPG File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Siemens JT2Go. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of HPG files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-21-233?
The severity of ZDI-21-233 is considered high due to its potential to disclose sensitive information.
How do I fix ZDI-21-233?
To fix ZDI-21-233, users should update to the latest version of Siemens JT2Go that addresses this vulnerability.
Who is affected by ZDI-21-233?
ZDI-21-233 affects users of Siemens JT2Go installations.
What types of exploit are possible with ZDI-21-233?
ZDI-21-233 can be exploited through user interaction by visiting a malicious page or opening a malicious file.
What information can be disclosed due to ZDI-21-233?
ZDI-21-233 may allow remote attackers to disclose sensitive information from affected installations.