First published: Thu Jul 01 2021(Updated: )
GNU LibreDWG 0.12.3.4163 through 0.12.3.4191 has a double-free in bit_chain_free (called from dwg_encode_MTEXT and dwg_encode_add_object).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GNU LibreDWG | >=0.12.3.4163<=0.12.3.4191 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-36080.
The severity of CVE-2021-36080 is high (8.8).
GNU LibreDWG versions 0.12.3.4163 through 0.12.3.4191 are affected.
The vulnerability can be exploited through the double-free in bit_chain_free function called from dwg_encode_MTEXT and dwg_encode_add_object.
Yes, a fix for CVE-2021-36080 is available. It can be found in the commit 9b6e0ff9ef02818df034fc42c3bd149a5ff89342 on the LibreDWG GitHub repository.