NULL Pointer Dereference in libredwg Affects LibreDWG Software
CVE-2021-39523

6.5MEDIUM

Key Information:

Vendor
Gnu
Status
Vendor
CVE Published:
20 September 2021

Summary

A NULL pointer dereference vulnerability exists in the libredwg library, particularly within the check_POLYLINE_handles() function in decode.c. This flaw allows attackers to exploit the system, which may lead to Denial of Service, ultimately disrupting service availability for users. It's essential for users of affected versions to implement security measures to mitigate potential risks.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.