CVE-2022-3159

The APDFL.dll contains a stack-based buffer overflow vulnerability that could be triggered while parsing specially crafted PDF files. This could allow an attacker to execute code in the context of the current process.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:siemens:jt2go:*:*:*:*:*:*:*:*
cpe:2.3:a:siemens:teamcenter_visualization:*:*:*:*:*:*:*:*
cpe:2.3:a:siemens:teamcenter_visualization:*:*:*:*:*:*:*:*
cpe:2.3:a:siemens:teamcenter_visualization:*:*:*:*:*:*:*:*

History

07 Nov 2023, 03:50

Type Values Removed Values Added
Summary The APDFL.dll contains a stack-based buffer overflow vulnerability that could be triggered while parsing specially crafted PDF files. This could allow an attacker to execute code in the context of the current process. The APDFL.dll contains a stack-based buffer overflow vulnerability that could be triggered while parsing specially crafted PDF files. This could allow an attacker to execute code in the context of the current process.

23 Jan 2023, 18:33

Type Values Removed Values Added
References (MISC) https://cert-portal.siemens.com/productcert/csaf/ssa-360681.json - (MISC) https://cert-portal.siemens.com/productcert/csaf/ssa-360681.json - Third Party Advisory
References (MISC) https://cert-portal.siemens.com/productcert/html/ssa-360681.html - (MISC) https://cert-portal.siemens.com/productcert/html/ssa-360681.html - Patch, Third Party Advisory
References (MISC) https://www.cisa.gov/uscert/ics/advisories/icsa-22-349-15 - (MISC) https://www.cisa.gov/uscert/ics/advisories/icsa-22-349-15 - Third Party Advisory, US Government Resource
First Time Siemens teamcenter Visualization
Siemens jt2go
Siemens
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8
CPE cpe:2.3:a:siemens:jt2go:*:*:*:*:*:*:*:*
cpe:2.3:a:siemens:teamcenter_visualization:*:*:*:*:*:*:*:*
CWE CWE-121 CWE-787

13 Jan 2023, 05:12

Type Values Removed Values Added
New CVE

Information

Published : 2023-01-13 01:15

Updated : 2023-12-10 14:48


NVD link : CVE-2022-3159

Mitre link : CVE-2022-3159

CVE.ORG link : CVE-2022-3159


JSON object : View

Products Affected

siemens

  • jt2go
  • teamcenter_visualization
CWE
CWE-787

Out-of-bounds Write

CWE-121

Stack-based Buffer Overflow