CVE-2023-22669: High severity opendesign drawings software development kit vulnerability
Parsing of DWG files in Open Design Alliance Drawings SDK before 2023.6 lacks proper validation of the length of user-supplied XRecord data prior to copying it to a fixed-length heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-22669.
What is the severity of CVE-2023-22669?
The severity of CVE-2023-22669 is high, with a severity value of 7.8.
What is the description of CVE-2023-22669?
CVE-2023-22669 is a vulnerability in the parsing of DWG files in Open Design Alliance Drawings SDK before version 2023.6, which lacks proper validation of the length of user-supplied XRecord data, allowing an attacker to execute code in the context of the current process.
What software is affected by CVE-2023-22669?
The Open Design Alliance Drawings SDK before version 2023.6 is affected by CVE-2023-22669.
How can I fix CVE-2023-22669?
To fix CVE-2023-22669, update to Open Design Alliance Drawings SDK version 2023.6 or later.