CVE Vulnerabilities

CVE-2022-29028

Loop with Unreachable Exit Condition ('Infinite Loop')

Published: May 20, 2022 | Modified: May 26, 2022
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu

A vulnerability has been identified in JT2Go (All versions < V13.3.0.3), Teamcenter Visualization V13.3 (All versions < V13.3.0.3), Teamcenter Visualization V14.0 (All versions < V14.0.0.1). The Tiff_Loader.dll is vulnerable to infinite loop condition while parsing specially crafted TIFF files. An attacker could leverage this vulnerability to crash the application causing denial of service condition.

Weakness

The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.

Affected Software

Name Vendor Start Version End Version
Jt2go Siemens * 13.3.0.3 (excluding)
Teamcenter_visualization Siemens 13.3 (including) 13.3.0.3 (excluding)
Teamcenter_visualization Siemens 14.0 (including) 14.0.0.1 (excluding)

References