CVE-2019-20910: High severity gnu libredwg vulnerability
Published Jul 16, 2020
·Updated
An issue was discovered in GNU LibreDWG through 0.9.3. Crafted input will lead to a heap-based buffer over-read in decodeR13R2000 in decode.c, a different vulnerability than CVE-2019-20011.
Affected Software
1 affected component
GNU LibreDWG<=0.9.3
Remediation
Event History
Jul 16, 2020
CVE Published
via MITRE·05:46 PM
Data Sourced
via MITRE·05:46 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-20910?
CVE-2019-20910 is classified as a moderate severity vulnerability.
2
How do I fix CVE-2019-20910?
To fix CVE-2019-20910, you should upgrade to GNU LibreDWG version 0.9.4 or later.
3
What impact does CVE-2019-20910 have?
CVE-2019-20910 can lead to a heap-based buffer over-read, potentially causing information leakage.
4
Which versions of GNU LibreDWG are affected by CVE-2019-20910?
CVE-2019-20910 affects versions of GNU LibreDWG up to and including 0.9.3.
5
Is CVE-2019-20910 related to any other vulnerabilities?
CVE-2019-20910 is a different vulnerability from CVE-2019-20011, despite their similarities.