CVE-2023-25222: Buffer Overflow
Published Mar 1, 2023
·Updated
A heap-based buffer overflow vulnerability exits in GNU LibreDWG v0.12.5 via the bitreadRC function at bits.c.
Affected Software
1 affected component
GNU LibreDWG=0.12.5
Event History
Mar 1, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is CVE-2023-25222?
CVE-2023-25222 is a heap-based buffer overflow vulnerability in GNU LibreDWG v0.12.5.
2
How does CVE-2023-25222 affect GNU LibreDWG?
CVE-2023-25222 affects GNU LibreDWG v0.12.5 through the bit_read_RC function in bits.c.
3
What is the severity of CVE-2023-25222?
CVE-2023-25222 has a severity rating of 8.8 (high).
4
What software versions are affected by CVE-2023-25222?
CVE-2023-25222 affects GNU LibreDWG v0.12.5.
5
Is there a fix available for CVE-2023-25222?
At the moment, there is no known fix available for CVE-2023-25222. It is recommended to follow the provided references for any updates or patches.