A flaw has been found in GNU libredwg up to 0.13.4.8160. This issue affects the function bitreadRC of the file bits.c of the component Dwgbmp Utility. This manipulation causes heap-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been published and may be used. Patch name: 8f03865f37f5d4ffd616fef802acc980be54d300. Applying a patch is the recommended action to fix this issue.
Heap buffer overflow vulnerability in LibreDWG versions v0.13.3.7571 up to v0.13.3.7835 allows a crafted DWG file to cause a Denial of Service (DoS) via the function decompressR2004section at decode.c.
LibreDWG 0.12.4.4313 through 0.12.4.4367 has an out-of-bounds write in dwgfreeBLOCKprivate (called from dwgfreeBLOCK and dwgfreeobject).
An issue was discovered in libredwg through v0.10.1.3751. A NULL pointer dereference exists in the function checkPOLYLINEhandles() located in decode.c. It allows an attacker to cause Denial of Service.
An issue was discovered in libredwg through v0.10.1.3751. A NULL pointer dereference exists in the function bitreadBB() located in bits.c. It allows an attacker to cause Denial of Service.
A heap-based buffer overflow vulnerability exists in LibreDWG 0.10.1 via the readsystempage function at libredwg-0.10.1/src/decoder2007.c:666:5, which causes a denial of service by submitting a dwg file.
An issue was discovered in GNU LibreDWG 0.10. Crafted input will lead to an memory leak in dwgdecodeeed ../../src/decode.c:3638.
A null pointer deference issue exists in GNU LibreDWG 0.10 via read2004compressedsection ../../src/decode.c:2337.
A null pointer deference issue exists in GNU LibreDWG 0.10 via getbmp ../../programs/dwgbmp.c:164.
A null pointer dereference issue exists in GNU LibreDWG 0.10.2641 via htmlescape ../../programs/escape.c:29. which causes a denial of service (application crash).
A null pointer deference issue exists in GNU LibreDWG 0.10.2641 via outputTEXT ../../programs/dwg2SVG.c:114, which causes a denial of service (application crash).
GNU LibreDWG before 0.11 allows NULL pointer dereferences via crafted input files.
An issue was discovered in GNU LibreDWG through 0.9.3. Crafted input will lead to denial of service in bitcalcCRC in bits.c, related to a for loop.
GNU LibreDWG 0.9.3.2564 has an attempted excessive memory allocation in readsectionsmap in decoder2007.c.
GNU LibreDWG 0.9.3.2564 has a NULL pointer dereference in getnextownedentity in dwg.c.
GNU LibreDWG 0.9.3.2564 has an invalid pointer dereference in dwgdynapientityvalue in dynapi.c (dynapi.c is generated by gen-dynapi.pl).
An issue was discovered in GNU LibreDWG before 0.93. Crafted input will lead to an attempted excessive memory allocation in dwgdecodeSPLINEprivate in dwg.spec.
An issue was discovered in GNU LibreDWG 0.92. Crafted input will lead to an attempted excessive memory allocation in dwgdecodeHATCHprivate in dwg.spec.
An issue was discovered in GNU LibreDWG before 0.93. Crafted input will lead to an attempted excessive memory allocation in decode3dsolid in dwg.spec.
An issue was discovered in GNU LibreDWG 0.92. Crafted input will lead to an attempted excessive memory allocation in dwgdecodeLWPOLYLINEprivate in dwg.spec.
dwgdecodeeed in decode.c in GNU LibreDWG before 0.6 leads to a double free (in dwgfreeeed in free.c) because it does not properly manage the obj->eed value after a free occurs.
dwgobjblockcontrolgetblockheaders in dwgapi.c in GNU LibreDWG 0.5.1048 allows remote attackers to cause a denial of service (NULL pointer dereference and SEGV) via a crafted dwg file.
getfirstownedobject in dwg.c in GNU LibreDWG 0.5.1036 allows remote attackers to cause a denial of service (SEGV).