CVE-2021-40160

Severity CVSS v4.0:
Pending analysis
Type:
CWE-125 Out-of-bounds Read
Publication date:
23/12/2021
Last modified:
01/05/2022

Description

PDFTron prior to 9.0.7 version may be forced to read beyond allocated boundaries when parsing a maliciously crafted PDF file. This vulnerability can be exploited to execute arbitrary code.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:autodesk:revit:*:*:*:*:*:*:*:* 2020 (including) 2020.2.5 (excluding)
cpe:2.3:a:autodesk:revit:*:*:*:*:*:*:*:* 2021 (including) 2021.1.4 (excluding)
cpe:2.3:a:autodesk:revit:*:*:*:*:*:*:*:* 2022 (including) 2022.1 (excluding)
cpe:2.3:a:autodesk:navisworks:*:*:*:*:*:*:*:* 2019 (including) 2019.6 (excluding)
cpe:2.3:a:autodesk:navisworks:*:*:*:*:*:*:*:* 2020 (including) 2020.4 (excluding)
cpe:2.3:a:autodesk:navisworks:*:*:*:*:*:*:*:* 2021 (including) 2021.3 (excluding)
cpe:2.3:a:autodesk:navisworks:*:*:*:*:*:*:*:* 2022 (including) 2022.1 (excluding)
cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:* 2022 (including) 2022.1.1 (excluding)
cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:* 2022 (including) 2022.1.1 (excluding)
cpe:2.3:a:autodesk:autocad:*:*:*:*:*:macos:*:* 2022 (including) 2022.2 (excluding)
cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:* 2022 (including) 2022.1.1 (excluding)
cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:* 2022 (including) 2022.1.1 (excluding)
cpe:2.3:a:autodesk:autocad_lt:*:*:*:*:*:*:*:* 2022 (including) 2022.1.1 (excluding)
cpe:2.3:a:autodesk:autocad_lt:*:*:*:*:*:macos:*:* 2022 (including) 2022.2 (excluding)
cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:* 2022 (including) 2022.1.1 (excluding)


References to Advisories, Solutions, and Tools