CVE-2021-28236: Null Pointer Dereference
Published Dec 2, 2021
·Updated
LibreDWG v0.12.3 was discovered to contain a NULL pointer dereference via outdxfb.c.
Affected Software
1 affected component
GNU LibreDWG=0.12.3
Event History
Dec 2, 2021
CVE Published
via MITRE·09:47 PM
Data Sourced
via MITRE·09:47 PM
Description
Frequently Asked Questions
1
What is CVE-2021-28236?
CVE-2021-28236 is a vulnerability in LibreDWG v0.12.3 that allows for a NULL pointer dereference via out_dxfb.c.
2
What is the severity of CVE-2021-28236?
The severity of CVE-2021-28236 is high with a CVSS score of 7.5.
3
How does CVE-2021-28236 impact LibreDWG v0.12.3?
CVE-2021-28236 allows for a NULL pointer dereference in the out_dxfb.c file of LibreDWG v0.12.3.
4
How can I fix CVE-2021-28236?
To fix CVE-2021-28236, it is recommended to update to a version of LibreDWG that addresses the NULL pointer dereference vulnerability.
5
Where can I find more information about CVE-2021-28236?
More information about CVE-2021-28236 can be found at the following reference: https://github.com/LibreDWG/libredwg/issues/324