CVE-2021-42585: Buffer Overflow
Published May 23, 2022
·Updated
A heap buffer overflow was discovered in copycompressedbytes in decoder2007.c in dwgread before 0.12.4 via a crafted dwg file.
Affected Software
1 affected component
GNU LibreDWG<0.12.4
Event History
May 23, 2022
CVE Published
via MITRE·10:35 AM
Data Sourced
via MITRE·10:35 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2021-42585.
2
What is the severity of CVE-2021-42585?
The severity of CVE-2021-42585 is high with a severity value of 8.8.
3
How does CVE-2021-42585 affect GNU LibreDWG?
CVE-2021-42585 affects GNU LibreDWG version 0.12.4 and prior.
4
What is the CWE ID for CVE-2021-42585?
The CWE ID for CVE-2021-42585 is CWE-119 and CWE-787.
5
How can I fix CVE-2021-42585?
To fix CVE-2021-42585, it is recommended to update to version 0.12.4 or later of GNU LibreDWG.