Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mm9v-95j4-52gp

Опубликовано: 21 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.8

Описание

A vulnerability has been identified in JT2Go (All versions < V13.3.0.3), Teamcenter Visualization V13.3 (All versions < V13.3.0.3), Teamcenter Visualization V14.0 (All versions < V14.0.0.1). The CGM_NIST_Loader.dll library is vulnerable to uninitialized pointer free while parsing specially crafted CGM files. An attacker could leverage this vulnerability to execute code in the context of the current process.

A vulnerability has been identified in JT2Go (All versions < V13.3.0.3), Teamcenter Visualization V13.3 (All versions < V13.3.0.3), Teamcenter Visualization V14.0 (All versions < V14.0.0.1). The CGM_NIST_Loader.dll library is vulnerable to uninitialized pointer free while parsing specially crafted CGM files. An attacker could leverage this vulnerability to execute code in the context of the current process.

EPSS

Процентиль: 52%
0.00293
Низкий

7.8 High

CVSS3

Дефекты

CWE-824

Связанные уязвимости

CVSS3: 7.8
nvd
больше 3 лет назад

A vulnerability has been identified in JT2Go (All versions < V13.3.0.3), Teamcenter Visualization V13.3 (All versions < V13.3.0.3), Teamcenter Visualization V14.0 (All versions < V14.0.0.1). The CGM_NIST_Loader.dll library is vulnerable to uninitialized pointer free while parsing specially crafted CGM files. An attacker could leverage this vulnerability to execute code in the context of the current process.

CVSS3: 7.8
fstec
почти 4 года назад

Уязвимость библиотеки CGM_NIST_Loader.dll инструмента для просмотра 3D JT JT2Go и системы управления жизненным циклом продукции Teamcenter Visualization, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 52%
0.00293
Низкий

7.8 High

CVSS3

Дефекты

CWE-824