Heap Buffer Overflow in LibreDWG Affects Open Source CAD Software
CVE-2022-33026

7.8HIGH

Key Information:

Vendor
Gnu
Status
Vendor
CVE Published:
23 June 2022

Summary

A serious heap buffer overflow vulnerability was identified in LibreDWG version 0.12.4.4608. The issue arises from the function bit_calc_CRC located in bits.c, which fails to properly handle memory, potentially allowing attackers to write outside the allocated buffer. This flaw could lead to data corruption or provide an opportunity for malicious code execution, posing a significant risk to users of the software.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.