CVE-2020-6612: High severity GNU LibreDWG vulnerability
Published Jan 8, 2020
·Updated
GNU LibreDWG 0.9.3.2564 has a heap-based buffer over-read in copycompressedbytes in decoder2007.c.
Affected Software
3 affected components
GNU LibreDWG=0.9.3.2564
openSUSE Backports SLE=15.0-sp1
openSUSE Leap=15.1
Event History
Jan 8, 2020
CVE Published
via MITRE·08:43 PM
Data Sourced
via MITRE·08:43 PM
Description
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2020-6612?
CVE-2020-6612 is classified as a high severity vulnerability due to the potential for heap-based buffer over-reads.
2
How do I fix CVE-2020-6612?
To mitigate CVE-2020-6612, upgrade to the latest version of GNU LibreDWG that resolves the buffer over-read issue.
3
What systems are affected by CVE-2020-6612?
CVE-2020-6612 specifically affects GNU LibreDWG version 0.9.3.2564 and certain openSUSE versions under specific configurations.
4
What is the nature of the vulnerability in CVE-2020-6612?
CVE-2020-6612 involves a heap-based buffer over-read in the copy_compressed_bytes function, which can lead to information disclosure.
5
Is there a known exploit for CVE-2020-6612?
As of now, there are no publicly known exploits specifically targeting CVE-2020-6612.