CVE-2018-14471: Null Pointer Dereference
Published Jul 20, 2018
·Updated
dwgobjblockcontrolgetblockheaders in dwgapi.c in GNU LibreDWG 0.5.1048 allows remote attackers to cause a denial of service (NULL pointer dereference and SEGV) via a crafted dwg file.
Affected Software
1 affected component
GNU LibreDWG<0.6
Event History
Jul 20, 2018
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-14471?
CVE-2018-14471 is classified as a denial of service vulnerability due to a NULL pointer dereference.
2
How does CVE-2018-14471 affect GNU LibreDWG?
CVE-2018-14471 allows remote attackers to exploit the vulnerability by sending a crafted DWG file to cause a service crash.
3
Which versions of GNU LibreDWG are affected by CVE-2018-14471?
CVE-2018-14471 affects GNU LibreDWG versions before 0.6.
4
How do I fix CVE-2018-14471?
To fix CVE-2018-14471, upgrade GNU LibreDWG to version 0.6 or later.
5
What is the impact of CVE-2018-14471 on system security?
CVE-2018-14471 can lead to service disruption, making the system unavailable to users.