CVE-2020-21836: Buffer Overflow
Published May 17, 2021
·Updated
A heap based buffer overflow vulnerability exists in GNU LibreDWG 0.10 via read2004sectionpreview ../../src/decode.c:3175.
Affected Software
1 affected component
GNU LibreDWG=0.10
Remediation
Event History
May 17, 2021
CVE Published
via MITRE·08:33 PM
Data Sourced
via MITRE·08:33 PM
Description
Data Sourced
via NVD·09:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2020-21836.
2
What is the title of the vulnerability?
The title of the vulnerability is 'A heap based buffer overflow vulnerability exists in GNU LibreDWG 0.10 via read_2004_section_preview.'
3
What is the affected software?
The affected software is GNU LibreDWG 0.10.
4
What is the severity of CVE-2020-21836?
The severity of CVE-2020-21836 is high with a CVSS score of 8.8.
5
How can I fix the vulnerability?
To fix the vulnerability, it is recommended to update GNU LibreDWG to a version that does not contain the vulnerability.