PT-2022-10716 · Siemens+1 · Siemens Jt2Go+1

Mat Powell

·

Published

2022-02-15

·

Updated

2023-11-30

·

CVE-2021-38405

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Datalogics APDFL library (affected versions not specified) Siemens JT2Go (affected versions not specified)
Description The issue is related to a memory corruption condition that occurs while parsing specially crafted PDF files. This could allow an attacker to execute code in the context of the current process. There is also a mention of an out-of-bounds write that could lead to remote code execution and an out-of-bounds read that could result in information disclosure.
Recommendations For the Datalogics APDFL library, consider disabling the PDF parsing functionality until a patch is available. For Siemens JT2Go, restrict access to PDF file parsing to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Buffer Overflow

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-38405
ZDI-22-336
ZDI-22-337
ZDI-22-339

Affected Products

Datalogics Apdfl Library
Siemens Jt2Go