CVE-2021-39521: Null Pointer Dereference
Published Sep 20, 2021
·Updated
An issue was discovered in libredwg through v0.10.1.3751. A NULL pointer dereference exists in the function bitreadBB() located in bits.c. It allows an attacker to cause Denial of Service.
Affected Software
1 affected component
GNU LibreDWG<=0.10.1.3751
Remediation
Patch Available
Event History
Sep 20, 2021
CVE Published
via MITRE·03:26 PM
Data Sourced
via MITRE·03:26 PM
Description
Data Sourced
via NVD·04:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability identifier for this issue in libredwg?
The vulnerability identifier for this issue in libredwg is CVE-2021-39521.
2
What is the severity of CVE-2021-39521?
The severity of CVE-2021-39521 is medium with a CVSS score of 6.5.
3
How does CVE-2021-39521 manifest?
CVE-2021-39521 manifests as a NULL pointer dereference in the function bit_read_BB() located in bits.c.
4
Which software versions are affected by CVE-2021-39521?
GNU LibreDWG versions up to and including 0.10.1.3751 are affected by CVE-2021-39521.
5
How can an attacker exploit CVE-2021-39521?
Exploiting CVE-2021-39521 allows an attacker to cause Denial of Service.