PT-2021-6582 · Ribbonsoft+2 · Dxflib+2
Lilith >_>
·
Published
2021-09-08
·
Updated
2024-06-15
·
CVE-2021-21897
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Ribbonsoft dxflib version 3.17.0
Description
A code execution issue exists in the DL Dxf::handleLWPolylineData functionality, related to a heap buffer overflow. This can be triggered by a specially-crafted .dxf file, allowing an attacker to potentially access confidential data, compromise its integrity, and cause a denial of service.
Recommendations
For version 3.17.0, consider disabling the DL Dxf::handleLWPolylineData functionality until a patch is available to prevent exploitation through malicious .dxf files. Restrict access to handling .dxf files to minimize the risk of triggering the heap buffer overflow. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Integer Underflow
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Debian
Suse
Dxflib