CVE-2023-36273: Buffer Overflow
Published Jun 23, 2023
·Updated
LibreDWG v0.12.5 was discovered to contain a heap buffer overflow via the function bitcalcCRC at bits.c.
Affected Software
1 affected component
GNU LibreDWG=0.12.5
Event History
Jun 23, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2023-36273?
CVE-2023-36273 is a vulnerability found in LibreDWG v0.12.5 that allows for a heap buffer overflow.
2
How severe is CVE-2023-36273?
CVE-2023-36273 has a severity rating of 8.8 (high).
3
How does CVE-2023-36273 affect GNU LibreDWG v0.12.5?
CVE-2023-36273 affects GNU LibreDWG v0.12.5 by allowing a heap buffer overflow through the function bit_calc_CRC at bits.c.
4
Is there a fix available for CVE-2023-36273?
Currently, there is no publicly available fix for CVE-2023-36273. It is recommended to follow the official advisory for any updates.
5
Where can I find more information about CVE-2023-36273?
More information about CVE-2023-36273 can be found at the following reference: [GitHub Issue #677](https://github.com/LibreDWG/libredwg/issues/677#BUG1).