CVE-2020-21840: Buffer Overflow
Published May 17, 2021
·Updated
A heap based buffer overflow vulnerability exits in GNU LibreDWG 0.10 via bitsearchsentinel ../../src/bits.c:1985.
Affected Software
1 affected component
GNU LibreDWG=0.10
Remediation
Event History
May 17, 2021
CVE Published
via MITRE·08:58 PM
Data Sourced
via MITRE·08:58 PM
Description
Data Sourced
via NVD·09:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2020-21840?
CVE-2020-21840 is a heap based buffer overflow vulnerability in GNU LibreDWG 0.10.
2
How severe is CVE-2020-21840?
CVE-2020-21840 has a severity value of 8.8 (high).
3
What software version is affected by CVE-2020-21840?
GNU LibreDWG 0.10 is affected by CVE-2020-21840.
4
How can CVE-2020-21840 be exploited?
CVE-2020-21840 can be exploited through a heap based buffer overflow in the bit_search_sentinel function.
5
Where can I find more information about CVE-2020-21840?
You can find more information about CVE-2020-21840 on the following references: [http://gnu.com](http://gnu.com), [http://libredwg.com](http://libredwg.com), [https://github.com/LibreDWG/libredwg/issues/188#issuecomment-574493513](https://github.com/LibreDWG/libredwg/issues/188#issuecomment-574493513)