Heap Buffer Overflow in LibreDWG Affects Open Source CAD Software
CVE-2022-33026
7.8HIGH
What is CVE-2022-33026?
A serious heap buffer overflow vulnerability was identified in LibreDWG version 0.12.4.4608. The issue arises from the function bit_calc_CRC located in bits.c, which fails to properly handle memory, potentially allowing attackers to write outside the allocated buffer. This flaw could lead to data corruption or provide an opportunity for malicious code execution, posing a significant risk to users of the software.