Headline
CVE-2021-38405
The Datalogics APDFL library used in affected products is vulnerable to memory corruption condition while parsing specially crafted PDF files. An attacker could leverage this vulnerability to execute code in the context of the current process.
%PDF-1.5 %���� 1 0 obj << /D [2 0 R /XYZ 70.866 771.024 null] >> endobj 3 0 obj << /D [2 0 R /XYZ 70.866 630.026 null] >> endobj 4 0 obj << /D [2 0 R /XYZ 70.866 534.081 null] >> endobj 5 0 obj << /D [6 0 R /XYZ 70.866 641.115 null] >> endobj 7 0 obj << /D [6 0 R /XYZ 70.866 534.211 null] >> endobj 8 0 obj << /D [9 0 R /XYZ 85.039 184.645 null] >> endobj 10 0 obj << /D [11 0 R /XYZ 70.866 498.606 null] >> endobj 12 0 obj << /S /GoTo /D [2 0 R /Fit] >> endobj 2 0 obj << /Contents 13 0 R /Type /Page /Resources 14 0 R /Parent 15 0 R /Annots [16 0 R 17 0 R 18 0 R 19 0 R 20 0 R 21 0 R 22 0 R 23 0 R 24 0 R 25 0 R 26 0 R 27 0 R 28 0 R] /MediaBox [0 0 595.276 841.89] >> endobj 16 0 obj << /A << /S /URI /Type /Action /URI (https://www.plm.automation.siemens.com/global/en/products/plm-components/jt2go.html) >> /C [0 1 1] /Subtype /Link /Type /Annot /H /I /Border [0 0 0] /Rect [303.117 434.609 518.276 446.026] >> endobj 18 0 obj << /A << /S /GoTo /D (section*.3) >> /Subtype /Link /C [1 0 0] /Type /Annot /H /I /Border [0 0 0] /Rect [302.649 397.254 433.497 409.931] >> endobj 19 0 obj << /A << /S /URI /Type /Action /URI (https://support.sw.siemens.com/) >> /C [0 1 1] /Subtype /Link /Type /Annot /H /I /Border [0 0 0] /Rect [303.117 368.658 446.757 380.075] >> endobj 20 0 obj << /A << /S /GoTo /D (section*.3) >> /Subtype /Link /C [1 0 0] /Type /Annot /H /I /Border [0 0 0] /Rect [302.649 343.258 433.497 355.936] >> endobj 21 0 obj << /A << /S /URI /Type /Action /URI (https://support.sw.siemens.com/) >> /C [0 1 1] /Subtype /Link /Type /Annot /H /I /Border [0 0 0] /Rect [303.117 307.292 446.757 318.709] >> endobj 22 0 obj << /A << /S /GoTo /D (section*.3) >> /Subtype /Link /C [1 0 0] /Type /Annot /H /I /Border [0 0 0] /Rect [302.649 281.892 433.497 294.569] >> endobj 23 0 obj << /A << /S /URI /Type /Action /URI (https://support.sw.siemens.com/) >> /C [0 1 1] /Subtype /Link /Type /Annot /H /I /Border [0 0 0] /Rect [303.117 245.925 446.757 257.342] >> endobj 24 0 obj << /A << /S /GoTo /D (section*.3) >> /Subtype /Link /C [1 0 0] /Type /Annot /H /I /Border [0 0 0] /Rect [302.649 220.525 433.497 233.203] >> endobj 25 0 obj << /A << /S /URI /Type /Action /URI (https://support.sw.siemens.com/) >> /C [0 1 1] /Subtype /Link /Type /Annot /H /I /Border [0 0 0] /Rect [303.117 185.616 446.757 197.033] >> endobj 26 0 obj << /A << /S /GoTo /D (section*.3) >> /Subtype /Link /C [1 0 0] /Type /Annot /H /I /Border [0 0 0] /Rect [302.649 160.216 433.497 172.894] >> endobj 27 0 obj << /A << /S /URI /Type /Action /URI (https://support.sw.siemens.com/) >> /C [0 1 1] /Subtype /Link /Type /Annot /H /I /Border [0 0 0] /Rect [303.117 131.621 446.757 143.038] >> endobj 28 0 obj << /A << /S /GoTo /D (section*.3) >> /Subtype /Link /C [1 0 0] /Type /Annot /H /I /Border [0 0 0] /Rect [302.649 106.221 433.497 118.898] >> endobj 29 0 obj << /A << /S /URI /Type /Action /URI (https://support.sw.siemens.com/) >> /C [0 1 1] /Subtype /Link /Type /Annot /H /I /Border [0 0 0] /Rect [303.117 732.465 446.757 743.882] >> endobj 30 0 obj << /A << /S /GoTo /D (section*.3) >> /Subtype /Link /C [1 0 0] /Type /Annot /H /I /Border [0 0 0] /Rect [302.649 707.065 433.497 719.743] >> endobj 31 0 obj << /A << /S /URI /Type /Action /URI (https://support.sw.siemens.com/) >> /C [0 1 1] /Subtype /Link /Type /Annot /H /I /Border [0 0 0] /Rect [303.117 678.47 446.757 689.887] >> endobj 32 0 obj << /A << /S /GoTo /D (section*.3) >> /Subtype /Link /C [1 0 0] /Type /Annot /H /I /Border [0 0 0] /Rect [302.649 653.07 433.497 665.747] >> endobj 14 0 obj << /ProcSet [/PDF /Text] /Font << /F51 33 0 R /F48 34 0 R >> >> endobj 13 0 obj << /Filter /FlateDecode /Length 2539 >> stream x��ZYs�F~ׯ�#Xe��>\��XR*�(VDZ�[I`���<�x�v�H��(А\��Ep�����}B�O~��]J�8�4���.1�X��Q�$�Q�{�/�I>]�N��i?��S��b�%�}.�34�C�z|s]�~���������<=��9���bp�� фmP��'’��I���9�D8�<�’’�T�()�z��O~;�Ѩ�&�3Jj�!�Vg�F���b �Ic�R�0m�����v��{�oS�0�fqXź�=�%d�v�f��[p����8�W�sF8���G�V �s�d��.!��!�Q�V���eѨ:8CJ�Iu� u\+�3B!·TaV����X٢�,���V��i�� ��9iڈpP���)k�V��4M��i��>�bU��}K$��*�����" ^��2e�Į�QL��H�:�-�Q+�T�=�F(�����ŨAwc�i }O�nq�U� @q0y�Մ)V��bt Ms��M���[�$�� ������y��5 7�+�=�ͺD(ӄ��Gm\~8a� ��uϦ ag������RC"�6" ǜ8�(�rU�|���g�a>]勦�ݯ��9��;��" ˍ|f����S5�X��q�lU�v�Ґ�����#�ȸ�=c� �s��l��Ve%O9����?����Sƈ0��ɖ�0��|f)�X��O�l��~�X����۞�h,��:̖̲���8���>�W?d�<ҽ�l� �RC�լ’`�Ж )(���.�U�YD3Z�ՏWW�nz�����w�����sM��“2���.K2��E>���Q^{’�[w��#��/I$���`�O��� ���*%���V�0�J��ah�c��Ҷ�X��wL��ר7q�-<�8L�����Ҷ;7p9�\��]x*�%j�W�2|���i1�1���9�N�wf�s6ϧ5!�nX��QB�;^+:�ܭJAY|����ǤA����]��J��MhFn@#���tu�@���#�m���Ngw�i��C�;�|� ��y�b��ޔO�ps8[��s�4�* 3i6�W�\��´`��!j���g+H�"�t<��*b��l�X�>uŔر�Xȑ�9Z�w0q���P��wfi ���)�� �T�TŤ��$�Ŏ�͞�����~(\k8���x#8��U�c�6�B��@W%�w��"X���U�IJ&�t�#��9_��,��XZ8v��2`��V[^��v�E�������b�CBExP���^�"�.�*D/��[0*����=�>y�U1vY9:��M�/��%�/�’Y1��~��<���9b�A���q���D���]^^�\�70h���D�� ��%�ڨݜQ��(K�ݯo�s�?���w�����W��_qf��;������QH�js��ZI�Ĩ<�6ʒ@kj�?��q�Ӈ_��K� �=r�$:�kGN�Bu_\��B�!��<�Ó�I����M�0�{TY�9�S*V ^��]�H��q��x���}��p�Up�0�=*E)���YO=^��������"���A%���9���Q��j�)�Q��x���N�(�7���H\�Q��aC�X�d�r��1�$��Js�U)����}X�_!��)�w�^��x[��f�G�S�?�1��1_��M�TM��!,vCb�j���җŞEQu���/�#�F`��0h���j5_�=;{||��’��d��lⓖ,#��=(�Y�Ylr�c�t?�}��g���d#g ��Q 4f2�M��.������M"�ɸ��F���E��9x�X�C�pdC���Kt��b6 ��M���YU m���Ɋh�?K���+[#-w0� �����T��ѩ�W���(ީ����fi�x��L�\�+��U�<���l�mڿ�д�v;��W�n���*�p��Sb6�~��w,ܕ;�|�v8�}{q�bO���B�(����:�8���������_U�-�{p��E� ����X;’M%>-���,V;Yb)>��a#@D� ���H"�N�^ I���> �a�߮2I�Q�7�@�_>$����_]�’�T��@"���@��ٔ`%8O�w�w�#�5H�a�[��z9:�{����#]e �0 �=ll���p�k�E�s�~Xo�둸s"_�_��0��çZ|%�+�j�-�!�ȅ�� ���@l6%X Ns�q���$�h};(��š��(����dݠ��@���f�8�g��R�zőH"{���?)���a�7��~u�x^±���z����`�w��@����E��D�ǯ��y��@�a���2 ��/�(�E����O�z0`�F��mV��!�A�R�iV|��|m�A�Tk5��0�>����aN5�/�9Gy/@����h|���f-��G�����������8�M���5�l��4���8�A��V}�¦r��B endstream endobj 35 0 obj << /D [2 0 R /XYZ 69.866 808.885 null] >> endobj 34 0 obj << /Subtype /Type1 /FirstChar 2 /Type /Font /BaseFont /ZMCVWG+NimbusSanL-Regu /FontDescriptor 36 0 R /Encoding 37 0 R /LastChar 169 /Widths 38 0 R >> endobj 33 0 obj << /Subtype /Type1 /FirstChar 44 /Type /Font /BaseFont /SWUMJD+NimbusSanL-Bold /FontDescriptor 39 0 R /Encoding 37 0 R /LastChar 122 /Widths 40 0 R >> endobj 41 0 obj << /D [2 0 R /XYZ 70.866 483.433 null] >> endobj 17 0 obj << /A << /S /URI /Type /Action /URI (https://www.plm.automation.siemens.com/global/en/products/plm-components/jt2go.html) >> /C [0 1 1] /Subtype /Link /Type /Annot /H /I /Border [0 0 0] /Rect [303.117 422.534 508.973 434.071] >> endobj 15 0 obj << /Kids [2 0 R 6 0 R 9 0 R 11 0 R] /Type /Pages /Count 4 >> endobj 42 0 obj << /A << /S /GoTo /D (section*.2) >> /Subtype /Link /C [1 0 0] /Type /Annot /H /I /Border [0 0 0] /Rect [386.143 551.028 524.579 562.564] >> endobj 43 0 obj << /A << /S /GoTo /D (section*.4) >> /Subtype /Link /C [1 0 0] /Type /Annot /H /I /Border [0 0 0] /Rect [147.498 533.215 309.548 544.632] >> endobj 44 0 obj << /A << /S /URI /Type /Action /URI (https://www.siemens.com/cert/operational-guidelines-industrial-security) >> /C [0 1 1] /Subtype /Link /Type /Annot /H /I /Border [0 0 0] /Rect [164.798 442.139 487.754 453.675] >> endobj 45 0 obj << /A << /S /URI /Type /Action /URI (https://www.siemens.com/industrialsecurity) >> /C [0 1 1] /Subtype /Link /Type /Annot /H /I /Border [0 0 0] /Rect [406.699 412.37 525.406 423.788] >> endobj 46 0 obj << /A << /S /URI /Type /Action /URI (https://www.first.org/cvss/) >> /C [0 1 1] /Subtype /Link /Type /Annot /H /I /Border [0 0 0] /Rect [131.954 194.473 248.203 206.01] >> endobj 47 0 obj << /A << /S /URI /Type /Action /URI (https://cwe.mitre.org/) >> /C [0 1 1] /Subtype /Link /Type /Annot /H /I /Border [0 0 0] /Rect [69.87 104.809 163.926 116.346] >> endobj 48 0 obj << /A << /S /URI /Type /Action /URI (https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:P/RL:T/RC:C) >> /C [0 1 1] /Subtype /Link /Type /Annot /H /I /Border [0 0 0] /Rect [224.029 677.459 507.105 691.407] >> endobj 49 0 obj << /ProcSet [/PDF /Text] /Font << /F51 33 0 R /F48 34 0 R >> >> endobj 6 0 obj << /Contents 50 0 R /Type /Page /Resources 49 0 R /Parent 15 0 R /Annots [29 0 R 30 0 R 31 0 R 32 0 R 42 0 R 43 0 R 44 0 R 45 0 R 51 0 R 46 0 R 47 0 R] /MediaBox [0 0 595.276 841.89] >> endobj 50 0 obj << /Filter /FlateDecode /Length 2891 >> stream x��Z[s�J~�����*3�0@j_tl�嬝xm%���< �Th�+��{�����l����~}�}g�������*v/сv&N�{��N�$^(“g2s>��y���ztD�{�Mщݼ�NK�ٷ��`Q�./}�}���U5[O����잌���9����HC�#6�^$�3]}��wf���{2��’�s�Pz��p_8�G;�Y�-��A�DZxa�i%��� �hi�h�@=_�H�N�B�v�62�#�j�v2��,]L���V��y�N���i�W%/ ��і�)����N�����9%�s"���!�2. “�m�n���.��/���Etk�g� �<-�_� �+O�z�x���MF�4Ր/�X����UVG$��EŘT����c�,�W���z�D��w�Fw|i��j�WpqoZ-N{*qХ�v+E =��D���}X3�GdWV��3c��aU-�u�M�R��T8M����1��ٯ(.���j]���i9������|�^#� J��q#oG���꿎�_A"W� $ѿ"ru�#��\�’G���G�P����.�E.���Z’���8ru���?n䭨ӘXu�S��s4|�MPu�H���jI �#�0N:��q@~���wwߙ��o���}��%L�����BC�KH���: u�d��|�q�~�sԫx 0�a�#)�پ��\]�G �W���`�H�~E�}(��X�Ԕ����M>,�?�~��hB�nL�E5�}��9-��lj>����Hp4�^4�6CwщF>#m�n���j�Əi��.��w�\��Π� Q߾&�VT�M��K����iOIL���$�~�����I���x�fP��g}����u��Y KƻPAEưD�G[����[W�����y1}0�����0λ��p��ۣ��4�g���"N.zh��Z@�_2Z 7X�-5�Y5�����=HY~k"®��U��p=#�߷�m��5[��蓭+`+v/���oZ�m���lc[�Ƥ��0�!�0~��Jr�py���n|����~�� D^���Ћボ#)��9��8{w5��. ��?�z�Pf�~r�y �(������������p���/�2rT,L�2h5��"rS�̻N�5;�"’ĥ8�z��o�J��/�UU��ܖ^��"M�!�vˬy%-p3GS���W�#�[�(ep�Lԑ��&��1�=��#F�B_UK���]�L�2�Tt�!��+�*ؙQ��g�,i�H�< 9�̼!lR�X����8ҽ��2�v���@I�1�Z}��A?�(�?��l��/$h��ӪD̝��`�r oG�”(ĥ���� 3�=m��1(��5��"/3f��`���!1�b�@*�#�e|� �+��9SU:{�He�m����(L�ۊ)ZU&ns:�چ�#=�}h��q9�a�W�%�$jO�$�� �r_֠b��tst�k�I����� �AG��}"�����x6˭u��P)7��p�������fq`D\�#E���e�ّѵ���1m�[i�w*�’�5B,�߶�2�ԑ’"�LjUJ� �J�g-��Rws��l�;��q����W ��HD�Q�\��#�������3ӳ�I�K{Jp;�f\ԅ�5=�s���� “�\��]V�UA[����j]s��فD�6�B��1=ݞ���#���B���b6�y0��{{=� ����5�������O�"��O�9O�*��Pbk�7|x�Of����x0i�\��@��ۃ�RĞ�^��(���e��U1\�ͅt���ޠ�t��&�*jN��\A�f+���5��Y���,i�M�f�TTKNV�kjH�-�!v����F! :��|^���|a��0pv�GK�>鴱`��U2�j?J�6M�mS�Y녑ı�’7�rҟ:F�S�hK�1d�� (�q���Y[����� ���i��H9��gE����i�[7R� \�$Oǜ�0=�^�`�#�C���ީ0�5�0��W���b���s�1�%�/r�q��i 7�t�ܟm�7�N�Vp�-*Ԥ]�h�E�����{6@�M�mkU��t�b�`-8�wTn��N %o[TP��p�P[�>ѫ��wA�����)*�x��_c������F*������*���T��N@Ҕ}ή���W����.��& �ڇD�x�e�N�����’H8_�JX�i]��P�j�^��K�����r�\7����kI�a�Ɯ�g��iC=�:�eV��M��}9՝ޛ�~��j� ���M��a��3�ʼ�[�m�i��U�x�j~:�Vק��h��&���=�~��(#~/���j�͵͛��6��~O�4M�d�o5QR+�c�%�6��K�b��.Ws���1 ����`#j+��,?��!�f�!R?V�bF��HF�� |�v����d �p�-���m�C��v�������J�BF��"�7���N����C5/�Χ��T3.��J;m��v�”w�`n(�p��0)(�4E���۶Q>�xA+C���3�[��L�PB����bıh��A�>���&�(��v 5b&q&S��pe�#�|g�גj,N�I�c��|E��~Mߥ�2�<��|���L�d����Jk�-Ӣ�������al�.Ǩ$�3���Yt��Ǵ�X����h�����g9��UG��2�c�5P�gL�X���Õm��3f��ѱO�h��/�-?Z�a�����Tb��wz���fJ�,�����&R`��NM���B��p?�B?���BH�e��{�CJr$|�?Y<�U E�(�� endstream endobj 52 0 obj << /D [6 0 R /XYZ 69.866 808.885 null] >> endobj 51 0 obj << /A << /S /URI /Type /Action /URI (https://www.siemens.com/industrialsecurity) >> /C [0 1 1] /Subtype /Link /Type /Annot /H /I /Border [0 0 0] /Rect [69.87 400.415 146.342 411.603] >> endobj 53 0 obj << /A << /S /URI /Type /Action /URI (https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C) >> /C [0 1 1] /Subtype /Link /Type /Annot /H /I /Border [0 0 0] /Rect [224.029 542.051 507.302 555.999] >> endobj 54 0 obj << /A << /S /URI /Type /Action /URI (https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C) >> /C [0 1 1] /Subtype /Link /Type /Annot /H /I /Border [0 0 0] /Rect [224.029 418.599 507.302 432.547] >> endobj 55 0 obj << /A << /S /URI /Type /Action /URI (https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C) >> /C [0 1 1] /Subtype /Link /Type /Annot /H /I /Border [0 0 0] /Rect [224.029 295.146 507.302 309.094] >> endobj 56 0 obj << /A << /S /URI /Type /Action /URI (https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C) >> /C [0 1 1] /Subtype /Link /Type /Annot /H /I /Border [0 0 0] /Rect [224.029 159.739 507.302 173.686] >> endobj 57 0 obj << /ProcSet [/PDF /Text] /Font << /F48 34 0 R >> >> endobj 9 0 obj << /Contents 58 0 R /Type /Page /Resources 57 0 R /Parent 15 0 R /Annots [48 0 R 53 0 R 54 0 R 55 0 R 56 0 R] /MediaBox [0 0 595.276 841.89] >> endobj 58 0 obj << /Filter /FlateDecode /Length 1746 >> stream x��[s�F���z�fʲW�.o�v.m�@�N�<� cM�H���ً���I3�>x����m?�58�8x�y6���sh�c�@b��8�Z#Ad0��Q���Eu�T�(��WQ��0��vK��]V��p藮#�\��~�*��Iuv1�@{}�ܹw��pd�@��`2�|���)�~0bZ�Vsp�����`����}P[�$��2&���L7��dE”-�!�b����$��”]E��u���<��0���ǝ`����;N�’��B�qDiGq��K1%]�8�}�������(�L�����m �T4
Related news
SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level account access to SolarWinds Web Console to execute arbitrary commands.
SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level account access to SolarWinds Web Console to execute arbitrary commands.