First published: Mon May 23 2022(Updated: )
A heap buffer overflow was discovered in copy_compressed_bytes in decode_r2007.c in dwgread before 0.12.4 via a crafted dwg file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GNU LibreDWG | <0.12.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-42585.
The severity of CVE-2021-42585 is high with a severity value of 8.8.
CVE-2021-42585 affects GNU LibreDWG version 0.12.4 and prior.
The CWE ID for CVE-2021-42585 is CWE-119 and CWE-787.
To fix CVE-2021-42585, it is recommended to update to version 0.12.4 or later of GNU LibreDWG.