CVE-2019-20909: Null Pointer Dereference
Published Jul 16, 2020
·Updated
An issue was discovered in GNU LibreDWG through 0.9.3. There is a NULL pointer dereference in the function dwgencodeLWPOLYLINE in dwg.spec.
Affected Software
1 affected component
GNU LibreDWG<=0.9.3
Remediation
Event History
Jul 16, 2020
CVE Published
via MITRE·05:46 PM
Data Sourced
via MITRE·05:46 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-20909?
CVE-2019-20909 has a severity level that can lead to a denial of service due to a NULL pointer dereference.
2
How do I fix CVE-2019-20909?
To fix CVE-2019-20909, upgrade GNU LibreDWG to version 0.9.4 or later, where the issue is resolved.
3
What software is affected by CVE-2019-20909?
CVE-2019-20909 affects GNU LibreDWG versions up to and including 0.9.3.
4
What is the impact of CVE-2019-20909?
The impact of CVE-2019-20909 is a potential crash of the application when processing specially crafted input.
5
Is there a workaround for CVE-2019-20909?
There are no known workarounds for CVE-2019-20909 other than upgrading to a patched version.