CVE-2020-6609: High severity GNU LibreDWG vulnerability
Published Jan 8, 2020
·Updated
GNU LibreDWG 0.9.3.2564 has a heap-based buffer over-read in readpagesmap in decoder2007.c.
Affected Software
3 affected components
GNU LibreDWG=0.9.3.2564
openSUSE Backports SLE=15.0-sp1
openSUSE Leap=15.1
Remediation
Event History
Jan 8, 2020
CVE Published
via MITRE·08:44 PM
Data Sourced
via MITRE·08:44 PM
Description
Data Sourced
via NVD·09:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2020-6609?
CVE-2020-6609 is classified as a moderate severity vulnerability.
2
How do I fix CVE-2020-6609?
To fix CVE-2020-6609, update GNU LibreDWG to the latest version that addresses this vulnerability.
3
What is the impact of CVE-2020-6609?
The impact of CVE-2020-6609 includes potential exploitation leading to a heap-based buffer over-read, which could compromise application stability.
4
Which versions of GNU LibreDWG are affected by CVE-2020-6609?
GNU LibreDWG version 0.9.3.2564 is specifically affected by CVE-2020-6609.
5
Is CVE-2020-6609 related to openSUSE?
Yes, CVE-2020-6609 also affects the openSUSE Backports and Leap distributions and should be addressed in their respective updates.