CVE-2021-42586: Buffer Overflow
Published May 23, 2022
·Updated
A heap buffer overflow was discovered in copybytes in decoder2007.c in dwgread before 0.12.4 via a crafted dwg file.
Affected Software
1 affected component
GNU LibreDWG<0.12.4
Remediation
Patch Available
Event History
May 23, 2022
CVE Published
via MITRE·10:39 AM
Data Sourced
via MITRE·10:39 AM
Description
Frequently Asked Questions
1
What is CVE-2021-42586?
CVE-2021-42586 is a heap buffer overflow vulnerability discovered in dwgread before version 0.12.4.
2
How does CVE-2021-42586 impact GNU LibreDWG?
CVE-2021-42586 can be exploited by a crafted DWG file and can lead to a heap buffer overflow in GNU LibreDWG before version 0.12.4.
3
What is the severity rating of CVE-2021-42586?
CVE-2021-42586 has a severity rating of 8.8, which is classified as high.
4
How can I fix CVE-2021-42586?
To fix CVE-2021-42586, update GNU LibreDWG to version 0.12.4 or later.
5
Where can I find more information about CVE-2021-42586?
You can find more information about CVE-2021-42586 in this GitHub issue: https://github.com/LibreDWG/libredwg/issues/350