When a user opens manipulated Tagged Image File Format (.tif) file received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9.0, the application crashes and becomes temporarily unavailable to the user until restart of the application
The product writes data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://launchpad.support.sap.com/#/notes/3121165 | permissions required |
https://wiki.scn.sap.com/wiki/display/PSR/SAP+Security+Patch+Day+-+December+2021 | vendor advisory |
https://www.zerodayinitiative.com/advisories/ZDI-21-1551/ | vdb entry third party advisory |