PT-2020-19176 · Gnu+1 · Gnu Libredwg+1

Linhlhq

·

Published

2020-01-08

·

Updated

2024-06-15

·

CVE-2020-6609

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions GNU LibreDWG version 0.9.3.2564
Description The issue is related to a heap-based buffer over-read in the read pages map function located in decode r2007.c.
Recommendations For GNU LibreDWG version 0.9.3.2564, consider updating to a newer version that addresses this issue, if available. As a temporary workaround, restrict access to the decode r2007.c module to minimize the risk of exploitation.

Exploit

Fix

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-6609
OPENSUSE-SU-2020:0096-1
OPENSUSE-SU-2020:0115-1
OPENSUSE-SU-2020_0096-1
OPENSUSE-SU-2024:10981-1

Affected Products

Gnu Libredwg
Suse