PT-2021-22609 · Libredwg · Libredwg

Seviezhou

·

Published

2021-09-20

·

Updated

2021-09-24

·

CVE-2021-39522

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: libredwg versions prior to v0.10.1.3751
Description: The issue is related to a heap-based buffer overflow in the bit wcs2len() function, located in bits.c. This overflow can occur due to improper handling of data, potentially leading to memory corruption and other security issues.
Recommendations: For versions prior to v0.10.1.3751, consider restricting access to the bit wcs2len() function in bits.c until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-39522

Affected Products

Libredwg