CVE-2019-20912: High severity gnu libredwg vulnerability
Published Jul 16, 2020
·Updated
An issue was discovered in GNU LibreDWG through 0.9.3. Crafted input will lead to a stack overflow in bits.c, possibly related to bitreadTF.
Affected Software
1 affected component
GNU LibreDWG<=0.9.3
Remediation
Event History
Jul 16, 2020
CVE Published
via MITRE·05:46 PM
Data Sourced
via MITRE·05:46 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-20912?
CVE-2019-20912 is classified as a critical vulnerability due to the potential for exploitation leading to a stack overflow.
2
How do I fix CVE-2019-20912?
To fix CVE-2019-20912, upgrade GNU LibreDWG to a version later than 0.9.3 where the vulnerability has been addressed.
3
What impact does CVE-2019-20912 have on affected systems?
CVE-2019-20912 can allow attackers to execute arbitrary code due to a stack overflow caused by crafted input.
4
Which versions of GNU LibreDWG are affected by CVE-2019-20912?
All versions of GNU LibreDWG up to and including 0.9.3 are affected by CVE-2019-20912.
5
Who can exploit the CVE-2019-20912 vulnerability?
Any unauthorized user can potentially exploit the CVE-2019-20912 vulnerability by providing specially crafted input.