CVE-2021-36080: Double Free
Published Jul 1, 2021
·Updated
GNU LibreDWG 0.12.3.4163 through 0.12.3.4191 has a double-free in bitchainfree (called from dwgencodeMTEXT and dwgencodeaddobject).
Affected Software
1 affected component
GNU LibreDWG>=0.12.3.4163<=0.12.3.4191
Remediation
Patch Available
Event History
Jul 1, 2021
CVE Published
via MITRE·02:47 AM
Data Sourced
via MITRE·02:47 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2021-36080.
2
What is the severity of CVE-2021-36080?
The severity of CVE-2021-36080 is high (8.8).
3
Which software versions are affected by CVE-2021-36080?
GNU LibreDWG versions 0.12.3.4163 through 0.12.3.4191 are affected.
4
How can the vulnerability CVE-2021-36080 be exploited?
The vulnerability can be exploited through the double-free in bit_chain_free function called from dwg_encode_MTEXT and dwg_encode_add_object.
5
Is there a fix or patch available for CVE-2021-36080?
Yes, a fix for CVE-2021-36080 is available. It can be found in the commit 9b6e0ff9ef02818df034fc42c3bd149a5ff89342 on the LibreDWG GitHub repository.