CVE-2021-39530: Buffer Overflow
Published Sep 20, 2021
·Updated
An issue was discovered in libredwg through v0.10.1.3751. bitwcs2nlen() in bits.c has a heap-based buffer overflow.
Affected Software
1 affected component
GNU LibreDWG<=0.10.1.3751
Remediation
Patch Available
Event History
Sep 20, 2021
CVE Published
via MITRE·03:26 PM
Data Sourced
via MITRE·03:26 PM
Description
Data Sourced
via NVD·04:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the CVE ID of this vulnerability?
The CVE ID of this vulnerability is CVE-2021-39530.
2
What is the severity level of CVE-2021-39530?
The severity level of CVE-2021-39530 is high (8.8).
3
What is the affected software version?
The affected software version is GNU LibreDWG up to and including v0.10.1.3751.
4
What is the description of this vulnerability?
This vulnerability is a heap-based buffer overflow in bit_wcs2nlen() function of libredwg.
5
Is there a fix available for this vulnerability?
At the time of writing, there is no available fix for this vulnerability. It is recommended to follow the recommendations provided by the software vendor or the CVE advisory.