First published: Mon Apr 10 2023(Updated: )
An issue was discovered in Open Design Alliance Drawings SDK before 2024.1. A crafted DWG file can force the SDK to reuse an object that has been freed. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Opendesign Drawings Sdk | <2024.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2023-26495.
The severity of CVE-2023-26495 is high with a severity value of 7.8.
The affected software of CVE-2023-26495 is Open Design Alliance Drawings SDK before 2024.1.
An attacker can exploit CVE-2023-26495 by crafting a malicious DWG file to force the SDK to reuse a freed object, allowing them to execute arbitrary code.
Yes, upgrading to Open Design Alliance Drawings SDK version 2024.1 or newer will fix CVE-2023-26495.