First published: Tue Jan 02 2024(Updated: )
Versions of the package libredwg before 0.12.5.6384 are vulnerable to Denial of Service (DoS) due to an out-of-bounds read involving section->num_pages in decode_r2007.c.
Credit: report@snyk.io
Affected Software | Affected Version | How to fix |
---|---|---|
GNU LibreDWG | <0.12.5.6384 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-26157 is classified as a Denial of Service (DoS) vulnerability.
CVE-2023-26157 can cause an out-of-bounds read, leading to potential application crashes or denial of service.
Versions of libredwg before 0.12.5.6384 are affected by CVE-2023-26157.
To fix CVE-2023-26157, upgrade libredwg to version 0.12.5.6384 or later.
The vulnerability in CVE-2023-26157 is located in the decode_r2007.c component, specifically involving section->num_pages.