CVE-2023-36274: Buffer Overflow
Published Jun 23, 2023
·Updated
LibreDWG v0.11 to v0.12.5 was discovered to contain a heap buffer overflow via the function bitwriteTF at bits.c.
Other sources
LibreDWG v0.12.5 was discovered to contain a heap buffer overflow via the function bitwriteTF at bits.c.
Affected Software
2 affected components
GNU LibreDWG=0.12.5
GNU LibreDWG>=0.11<=0.12.5
Remediation
Event History
Jun 23, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·03:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2023-36274?
CVE-2023-36274 is a heap buffer overflow vulnerability found in LibreDWG v0.12.5.
2
How does CVE-2023-36274 impact GNU LibreDWG?
CVE-2023-36274 can allow an attacker to execute arbitrary code or cause a denial-of-service attack in GNU LibreDWG.
3
What is the severity of CVE-2023-36274?
CVE-2023-36274 has a severity score of 8.8 (high).
4
How can I fix CVE-2023-36274?
To fix CVE-2023-36274, users should update to a patched version of GNU LibreDWG.
5
Are there any references for CVE-2023-36274?
Yes, you can find more information about CVE-2023-36274 at: [Link to GitHub Issue](https://github.com/LibreDWG/libredwg/issues/677#BUG2)