Heap Buffer Overflow Vulnerability in LibreDWG by LibreDWG
CVE-2022-45332

7.8HIGH

Key Information:

Vendor

Gnu

Status
Vendor
CVE Published:
30 November 2022

What is CVE-2022-45332?

A heap buffer overflow was identified in LibreDWG version 0.12.4.4643, particularly within the function decode_preR13_section_hdr at decode_r11.c. This flaw can potentially lead to memory corruption, which may allow an attacker to execute arbitrary code or cause unexpected behavior in the application. Users of affected versions should apply updates or patches as they become available to mitigate this security risk.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.