CVE-2019-20013: Medium severity gnu libredwg vulnerability
Published Dec 27, 2019
·Updated
An issue was discovered in GNU LibreDWG before 0.93. Crafted input will lead to an attempted excessive memory allocation in decode3dsolid in dwg.spec.
Affected Software
3 affected components
GNU LibreDWG<0.9.3
openSUSE Backports SLE=15.0-sp1
openSUSE Leap=15.1
Remediation
Patch Available
Event History
Dec 27, 2019
CVE Published
via MITRE·12:14 AM
Data Sourced
via MITRE·12:14 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-20013?
CVE-2019-20013 is classified as a high severity vulnerability due to the potential for excessive memory allocation leading to resource exhaustion.
2
How do I fix CVE-2019-20013?
To fix CVE-2019-20013, upgrade GNU LibreDWG to version 0.9.3 or later.
3
What systems are affected by CVE-2019-20013?
CVE-2019-20013 affects GNU LibreDWG versions prior to 0.9.3 and specific versions of openSUSE Backports and SUSE openSUSE.
4
What type of attack does CVE-2019-20013 enable?
CVE-2019-20013 enables attackers to perform denial of service attacks by triggering excessive memory allocation.
5
Is CVE-2019-20013 easy to exploit?
Yes, CVE-2019-20013 can be exploited with crafted input, making it relatively easy for attackers to trigger the vulnerability.