A flaw has been found in GNU libredwg up to 0.13.4.8160. This issue affects the function bitreadRC of the file bits.c of the component Dwgbmp Utility. This manipulation causes heap-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been published and may be used. Patch name: 8f03865f37f5d4ffd616fef802acc980be54d300. Applying a patch is the recommended action to fix this issue.
An issue was discovered in GNU LibreDWG 0.10. Crafted input will lead to an memory leak in dwgdecodeeed ../../src/decode.c:3638.
A null pointer deference issue exists in GNU LibreDWG 0.10 via read2004compressedsection ../../src/decode.c:2337.
A null pointer deference issue exists in GNU LibreDWG 0.10 via getbmp ../../programs/dwgbmp.c:164.
A null pointer dereference issue exists in GNU LibreDWG 0.10.2641 via htmlescape ../../programs/escape.c:29. which causes a denial of service (application crash).
A null pointer deference issue exists in GNU LibreDWG 0.10.2641 via outputTEXT ../../programs/dwg2SVG.c:114, which causes a denial of service (application crash).
An issue was discovered in libredwg through v0.10.1.3751. A NULL pointer dereference exists in the function checkPOLYLINEhandles() located in decode.c. It allows an attacker to cause Denial of Service.
An issue was discovered in libredwg through v0.10.1.3751. A NULL pointer dereference exists in the function bitreadBB() located in bits.c. It allows an attacker to cause Denial of Service.
GNU LibreDWG 0.9.3.2564 has an invalid pointer dereference in dwgdynapientityvalue in dynapi.c (dynapi.c is generated by gen-dynapi.pl).
GNU LibreDWG 0.9.3.2564 has a NULL pointer dereference in getnextownedentity in dwg.c.
GNU LibreDWG 0.9.3.2564 has an attempted excessive memory allocation in readsectionsmap in decoder2007.c.
Heap buffer overflow vulnerability in LibreDWG versions v0.13.3.7571 up to v0.13.3.7835 allows a crafted DWG file to cause a Denial of Service (DoS) via the function decompressR2004section at decode.c.
LibreDWG 0.12.4.4313 through 0.12.4.4367 has an out-of-bounds write in dwgfreeBLOCKprivate (called from dwgfreeBLOCK and dwgfreeobject).
dwgobjblockcontrolgetblockheaders in dwgapi.c in GNU LibreDWG 0.5.1048 allows remote attackers to cause a denial of service (NULL pointer dereference and SEGV) via a crafted dwg file.
getfirstownedobject in dwg.c in GNU LibreDWG 0.5.1036 allows remote attackers to cause a denial of service (SEGV).
dwgdecodeeed in decode.c in GNU LibreDWG before 0.6 leads to a double free (in dwgfreeeed in free.c) because it does not properly manage the obj->eed value after a free occurs.
An issue was discovered in GNU LibreDWG through 0.9.3. Crafted input will lead to denial of service in bitcalcCRC in bits.c, related to a for loop.
An issue was discovered in GNU LibreDWG 0.92. Crafted input will lead to an attempted excessive memory allocation in dwgdecodeLWPOLYLINEprivate in dwg.spec.
An issue was discovered in GNU LibreDWG before 0.93. Crafted input will lead to an attempted excessive memory allocation in decode3dsolid in dwg.spec.
An issue was discovered in GNU LibreDWG before 0.93. Crafted input will lead to an attempted excessive memory allocation in dwgdecodeSPLINEprivate in dwg.spec.
An issue was discovered in GNU LibreDWG 0.92. Crafted input will lead to an attempted excessive memory allocation in dwgdecodeHATCHprivate in dwg.spec.
A heap-based buffer overflow vulnerability exists in LibreDWG 0.10.1 via the readsystempage function at libredwg-0.10.1/src/decoder2007.c:666:5, which causes a denial of service by submitting a dwg file.
GNU LibreDWG before 0.11 allows NULL pointer dereferences via crafted input files.