CVE-2021-43336
Description
An Out-of-Bounds Write vulnerability exists when reading a DXF or DWG file using Open Design Alliance Drawings SDK before 2022.11. The specific issue exists within the parsing of DXF and DWG files. Crafted data in a DXF or DWG file (an invalid number of properties) can trigger a write operation past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.
Risk Information
Base Score
7.8
MODERATE
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.421
Associated Vulnerability
| Vulnerability | OS Platform |
|---|---|
| Multiple Vulnerabilities are affected in Siemens Teamcenter Visualization 13.1.0 | Windows |
| Vulnerabilities CVE-2021-43336 are affected in JT2Go 2.3 | Windows |
| Vulnerabilities CVE-2021-43336 are affected in Siemens Teamcenter Visualization 12.4.0.12 | Windows |
| Vulnerabilities CVE-2021-43336 are affected in Siemens Teamcenter Visualization 13.3.0.0 | Windows |
Patch Details
Click to see the patches provided by ManageEngine for this CVE
| Patch ID | Patch Description |
|---|---|
| PATCH-351601 | JT2Go (2506.0.25240) |
References
https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234