CVE-2022-33034: High severity gnu libredwg vulnerability
Published Jun 22, 2022
·Updated
LibreDWG v0.12.4.4608 was discovered to contain a stack overflow via the function copybytes at decoder2007.c.
Affected Software
1 affected component
GNU LibreDWG=0.12.4.4608
Event History
Jun 22, 2022
CVE Published
via MITRE·01:33 PM
Data Sourced
via MITRE·01:33 PM
Description
Frequently Asked Questions
1
What is CVE-2022-33034?
CVE-2022-33034 is a stack overflow vulnerability found in LibreDWG v0.12.4.4608.
2
What is the severity of CVE-2022-33034?
CVE-2022-33034 has a severity score of 7.8, which is considered high.
3
How does CVE-2022-33034 affect LibreDWG?
CVE-2022-33034 affects GNU LibreDWG version 0.12.4.4608, potentially leading to a stack overflow through the function copy_bytes at decode_r2007.c.
4
Is there a fix for CVE-2022-33034?
At the moment, there is no official fix available for CVE-2022-33034. It is recommended to monitor the official LibreDWG project for updates and patches.
5
Where can I find more information about CVE-2022-33034?
You can find more information about CVE-2022-33034 on the GitHub issue page: https://github.com/LibreDWG/libredwg/issues/494.