CVE-2020-6614: High severity GNU LibreDWG vulnerability
Published Jan 8, 2020
·Updated
GNU LibreDWG 0.9.3.2564 has a heap-based buffer over-read in bfrread in decode.c.
Affected Software
3 affected components
GNU LibreDWG=0.9.3.2564
openSUSE Backports SLE=15.0-sp1
openSUSE Leap=15.1
Event History
Jan 8, 2020
CVE Published
via MITRE·08:43 PM
Data Sourced
via MITRE·08:43 PM
Description
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2020-6614?
CVE-2020-6614 is classified as a moderate severity vulnerability due to its potential to cause heap-based buffer over-read.
2
How do I fix CVE-2020-6614?
To fix CVE-2020-6614, upgrade GNU LibreDWG to the latest available version that addresses this vulnerability.
3
What versions are affected by CVE-2020-6614?
CVE-2020-6614 specifically affects GNU LibreDWG version 0.9.3.2564 and certain releases of openSUSE.
4
What type of vulnerability is CVE-2020-6614?
CVE-2020-6614 is a heap-based buffer over-read vulnerability found in the bfr_read function in decode.c.
5
Can CVE-2020-6614 lead to data leakage?
Yes, CVE-2020-6614 may potentially allow an attacker to read sensitive data from memory due to the buffer over-read.