PT-2020-19179 · Gnu+1 · Gnu Libredwg+1

Linhlhq

·

Published

2020-01-08

·

Updated

2022-09-12

·

CVE-2020-6612

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions GNU LibreDWG version 0.9.3.2564
Description The issue is related to a heap-based buffer over-read in the copy compressed bytes function located in decode r2007.c.
Recommendations For GNU LibreDWG version 0.9.3.2564, consider updating to a newer version that addresses this issue, if available. As a temporary workaround, restrict access to the decode r2007.c module to minimize the risk of exploitation.

Exploit

Fix

Out of bounds Read

Weakness Enumeration

Related Identifiers

CVE-2020-6612
OPENSUSE-SU-2020:0096-1
OPENSUSE-SU-2020:0115-1
OPENSUSE-SU-2020_0096-1

Affected Products

Gnu Libredwg
Suse