CVE-2019-20914: Null Pointer Dereference
Published Jul 16, 2020
·Updated
An issue was discovered in GNU LibreDWG through 0.9.3. There is a NULL pointer dereference in the function dwgencodecommonentityhandledata in commonentityhandledata.spec.
Affected Software
1 affected component
GNU LibreDWG<=0.9.3
Remediation
Event History
Jul 16, 2020
CVE Published
via MITRE·05:46 PM
Data Sourced
via MITRE·05:46 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-20914?
CVE-2019-20914 has been classified as a moderate severity vulnerability due to its potential for causing a crash.
2
How do I fix CVE-2019-20914?
To fix CVE-2019-20914, update to a version of GNU LibreDWG later than 0.9.3.
3
What causes CVE-2019-20914?
CVE-2019-20914 is caused by a NULL pointer dereference in the dwg_encode_common_entity_handle_data function.
4
Which versions of GNU LibreDWG are affected by CVE-2019-20914?
CVE-2019-20914 affects GNU LibreDWG versions up to and including 0.9.3.
5
Is CVE-2019-20914 exploitable by remote attackers?
CVE-2019-20914 is not typically considered remote exploitable, as it requires user interaction to trigger the vulnerability.