Heap Use-After-Free Vulnerability in LibreDWG Software by LibreDWG
CVE-2022-33027

7.8HIGH

Key Information:

Vendor
Gnu
Status
Vendor
CVE Published:
23 June 2022

Summary

A heap-use-after-free vulnerability was identified in LibreDWG v0.12.4.4608, specifically within the dwg_add_handleref function located in dwg.c. This flaw can potentially allow an attacker to exploit the system memory, leading to unpredictable behavior and security risks. Users are advised to review their installations and consider applying necessary mitigations.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.