First published: Mon May 23 2022(Updated: )
A heap buffer overflow was discovered in copy_bytes in decode_r2007.c in dwgread before 0.12.4 via a crafted dwg file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GNU LibreDWG | <0.12.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-42586 is a heap buffer overflow vulnerability discovered in dwgread before version 0.12.4.
CVE-2021-42586 can be exploited by a crafted DWG file and can lead to a heap buffer overflow in GNU LibreDWG before version 0.12.4.
CVE-2021-42586 has a severity rating of 8.8, which is classified as high.
To fix CVE-2021-42586, update GNU LibreDWG to version 0.12.4 or later.
You can find more information about CVE-2021-42586 in this GitHub issue: https://github.com/LibreDWG/libredwg/issues/350