Description
A vulnerability has been identified in JT2Go (All versions < V2312.0004), Parasolid V35.1 (All versions < V35.1.254), Parasolid V36.0 (All versions < V36.0.207), Parasolid V36.1 (All versions < V36.1.147), Teamcenter Visualization V14.2 (All versions < V14.2.0.12), Teamcenter Visualization V14.3 (All versions < V14.3.0.9), Teamcenter Visualization V2312 (All versions < V2312.0004). The affected applications contain a null pointer dereference vulnerability while parsing specially crafted X_T files. An attacker could leverage this vulnerability to crash the application causing denial of service condition.
Problem types
CWE-476: NULL Pointer Dereference
Product status
Any version before V2312.0004
Any version before V35.1.254
Any version before V36.0.207
Any version before V36.1.147
Any version before V14.2.0.12
Any version before V14.3.0.9
Any version before V2312.0004
References
cert-portal.siemens.com/productcert/html/ssa-222019.html
cert-portal.siemens.com/productcert/html/ssa-771940.html