CVE-2019-20009: Medium severity gnu libredwg vulnerability
Published Dec 27, 2019
·Updated
An issue was discovered in GNU LibreDWG before 0.93. Crafted input will lead to an attempted excessive memory allocation in dwgdecodeSPLINEprivate in dwg.spec.
Affected Software
3 affected components
GNU LibreDWG<0.9.3
openSUSE Backports SLE=15.0-sp1
openSUSE Leap=15.1
Remediation
Patch Available
Event History
Dec 27, 2019
CVE Published
via MITRE·12:15 AM
Data Sourced
via MITRE·12:15 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-20009?
CVE-2019-20009 has been classified as a medium severity vulnerability due to the potential for excessive memory allocation leading to denial of service.
2
How do I fix CVE-2019-20009?
To mitigate CVE-2019-20009, upgrade GNU LibreDWG to version 0.9.3 or later.
3
What versions of software are affected by CVE-2019-20009?
CVE-2019-20009 affects GNU LibreDWG versions prior to 0.9.3 and specific versions of openSUSE Backports and openSUSE Leap.
4
What kind of attack does CVE-2019-20009 enable?
CVE-2019-20009 enables attackers to cause excessive memory allocation through crafted input, potentially leading to a denial of service.
5
Is there a public exploit for CVE-2019-20009?
As of now, there are no publicly available exploits reported for CVE-2019-20009.