CVE-2020-23861: Buffer Overflow
A heap-based buffer overflow vulnerability exists in LibreDWG 0.10.1 via the readsystempage function at libredwg-0.10.1/src/decoder2007.c:666:5, which causes a denial of service by submitting a dwg file.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this heap-based buffer overflow vulnerability?
The vulnerability ID for this heap-based buffer overflow vulnerability is CVE-2020-23861.
What is the severity of CVE-2020-23861?
The severity of CVE-2020-23861 is medium with a CVSS score of 5.5.
What software is affected by CVE-2020-23861?
The GNU LibreDWG version 0.10.1 is affected by CVE-2020-23861.
How does CVE-2020-23861 cause a denial of service?
CVE-2020-23861 causes a denial of service by submitting a malicious DWG file that triggers a heap-based buffer overflow in the read_system_page function of LibreDWG.
Is there a fix available for CVE-2020-23861?
At the time of this writing, there is no known fix available for CVE-2020-23861. It is recommended to follow the recommendations provided by the vendor or software developer.