Off-by-one in JT2Go and Teamcenter Visualization - CVE-2021-44007
Published: January 6, 2022
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to an off-by-one error in the heap while parsing specially crafted TIFF files. A remote attacker can trick a victim to open a specially crafted file, trigger an off-by-one error and cause a denial of service condition on the target system.
Affected software
Teamcenter Visualization
How to mitigate CVE-2021-44007
Teamcenter Visualization - update to 13.2.0.5