First published: Mon May 17 2021(Updated: )
A heap based buffer overflow vulnerability exists in GNU LibreDWG 0.10 via read_2004_compressed_section ../../src/decode.c:2379.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GNU LibreDWG | =0.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-21827 is a heap-based buffer overflow vulnerability in GNU LibreDWG 0.10.
CVE-2020-21827 affects GNU LibreDWG 0.10.
The severity of CVE-2020-21827 is high with a CVSS score of 7.8.
To fix CVE-2020-21827, update GNU LibreDWG to a version that is not affected by the vulnerability.
You can find more information about CVE-2020-21827 at the following references: <a href="http://gnu.com">http://gnu.com</a>, <a href="https://cwe.mitre.org/data/definitions/122.html">https://cwe.mitre.org/data/definitions/122.html</a>, <a href="https://github.com/LibreDWG/libredwg/issues/183">https://github.com/LibreDWG/libredwg/issues/183</a>.