First published: Mon May 17 2021(Updated: )
A heap based buffer overflow vulnerability exits in GNU LibreDWG 0.10 via bit_search_sentinel ../../src/bits.c:1985.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GNU LibreDWG | =0.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-21840 is a heap based buffer overflow vulnerability in GNU LibreDWG 0.10.
CVE-2020-21840 has a severity value of 8.8 (high).
GNU LibreDWG 0.10 is affected by CVE-2020-21840.
CVE-2020-21840 can be exploited through a heap based buffer overflow in the bit_search_sentinel function.
You can find more information about CVE-2020-21840 on the following references: [http://gnu.com](http://gnu.com), [http://libredwg.com](http://libredwg.com), [https://github.com/LibreDWG/libredwg/issues/188#issuecomment-574493513](https://github.com/LibreDWG/libredwg/issues/188#issuecomment-574493513)