CVE-2023-36272: Buffer Overflow
Published Jun 23, 2023
·Updated
LibreDWG v0.10 to v0.12.5 was discovered to contain a heap buffer overflow via the function bitutf8toTU at bits.c.
Other sources
LibreDWG v0.12.5 was discovered to contain a heap buffer overflow via the function bitutf8toTU at bits.c.
Affected Software
2 affected components
GNU LibreDWG=0.12.5
GNU LibreDWG>=0.10<=0.12.5
Remediation
Event History
Jun 23, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·03:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-36272?
The severity of CVE-2023-36272 is high with a CVSS score of 8.8.
2
What is the vulnerability in LibreDWG v0.12.5?
The vulnerability in LibreDWG v0.12.5 is a heap buffer overflow via the function bit_utf8_to_TU at bits.c.
3
Which software version is affected by CVE-2023-36272?
CVE-2023-36272 affects GNU LibreDWG version 0.12.5.
4
How can the heap buffer overflow vulnerability be exploited?
The heap buffer overflow vulnerability in LibreDWG v0.12.5 can be exploited by manipulating the bit_utf8_to_TU function in bits.c.
5
Is there a fix or patch available for CVE-2023-36272?
Currently, there is no available fix or patch for CVE-2023-36272. It is recommended to update to a newer version of LibreDWG when one becomes available.