CVE-2021-44003

A vulnerability has been identified in JT2Go (All versions < V13.2.0.5), Teamcenter Visualization (All versions < V13.2.0.5). The Tiff_Loader.dll is vulnerable to use of uninitialized memory while parsing user supplied TIFF files. This could allow an attacker to cause a denial-of-service condition.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:siemens:jt2go:*:*:*:*:*:*:*:*
cpe:2.3:a:siemens:teamcenter_visualization:*:*:*:*:*:*:*:*

History

25 Jul 2022, 10:38

Type Values Removed Values Added
CWE CWE-457 CWE-908

15 Dec 2021, 13:25

Type Values Removed Values Added
CPE cpe:2.3:a:siemens:jt2go:*:*:*:*:*:*:*:*
cpe:2.3:a:siemens:teamcenter_visualization:*:*:*:*:*:*:*:*
References (CONFIRM) https://cert-portal.siemens.com/productcert/pdf/ssa-595101.pdf - (CONFIRM) https://cert-portal.siemens.com/productcert/pdf/ssa-595101.pdf - Patch, Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : 4.3
v3 : 5.5

14 Dec 2021, 12:28

Type Values Removed Values Added
New CVE

Information

Published : 2021-12-14 12:15

Updated : 2023-12-10 14:09


NVD link : CVE-2021-44003

Mitre link : CVE-2021-44003

CVE.ORG link : CVE-2021-44003


JSON object : View

Products Affected

siemens

  • teamcenter_visualization
  • jt2go
CWE
CWE-908

Use of Uninitialized Resource

CWE-457

Use of Uninitialized Variable