First published: Wed Jun 22 2022(Updated: )
LibreDWG v0.12.4.4608 was discovered to contain a heap-use-after-free via the function decode_preR13_section at decode_r11.c.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GNU LibreDWG |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for the LibreDWG heap-use-after-free vulnerability is CVE-2022-33025.
The severity of CVE-2022-33025 is high with a CVSS score of 7.8.
The GNU LibreDWG software is affected by CVE-2022-33025.
The CWE ID for the LibreDWG heap-use-after-free vulnerability is CWE-416.
You can find more information about CVE-2022-33025 on the GitHub page for LibreDWG: https://github.com/LibreDWG/libredwg/issues/487