CVE-2023-26157: High severity gnu libredwg vulnerability
Published Jan 2, 2024
·Updated
Versions of the package libredwg before 0.12.5.6384 are vulnerable to Denial of Service (DoS) due to an out-of-bounds read involving section->numpages in decoder2007.c.
Affected Software
1 affected component
GNU LibreDWG<0.12.5.6384
Remediation
Patch Available
Event History
Jan 2, 2024
CVE Published
05:00 AM
Data Sourced
05:00 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-26157?
CVE-2023-26157 is classified as a Denial of Service (DoS) vulnerability.
2
How does CVE-2023-26157 affect affected software?
CVE-2023-26157 can cause an out-of-bounds read, leading to potential application crashes or denial of service.
3
Which versions of libredwg are affected by CVE-2023-26157?
Versions of libredwg before 0.12.5.6384 are affected by CVE-2023-26157.
4
How do I fix CVE-2023-26157?
To fix CVE-2023-26157, upgrade libredwg to version 0.12.5.6384 or later.
5
What component is responsible for the CVE-2023-26157 vulnerability?
The vulnerability in CVE-2023-26157 is located in the decode_r2007.c component, specifically involving section->num_pages.