PT-2022-6400 · Jt2Go+2 · Jt2Go+2
Michael Heinz
+1
·
Published
2022-12-13
·
Updated
2023-01-23
·
CVE-2022-3161
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
JT2Go (affected versions not specified)
Teamcenter Visualization (affected versions not specified)
Description
The issue is related to a memory corruption vulnerability in the APDFL.dll library, which occurs when parsing specially crafted PDF files. This could allow an attacker to execute code in the context of the current process.
Recommendations
For JT2Go, consider disabling the use of the APDFL.dll library until a patch is available.
For Teamcenter Visualization, restrict access to the APDFL.dll library to minimize the risk of exploitation.
Avoid using the APDFL.dll library for parsing PDF files until the issue is resolved.
Fix
Memory Corruption
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Apdfl.Dll
Jt2Go
Teamcenter Visualization