PT-2021-6582 · Ribbonsoft+2 · Dxflib+2

Lilith >_>

·

Published

2021-09-08

·

Updated

2024-06-15

·

CVE-2021-21897

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Ribbonsoft dxflib version 3.17.0
Description A code execution issue exists in the DL Dxf::handleLWPolylineData functionality, related to a heap buffer overflow. This can be triggered by a specially-crafted .dxf file, allowing an attacker to potentially access confidential data, compromise its integrity, and cause a denial of service.
Recommendations For version 3.17.0, consider disabling the DL Dxf::handleLWPolylineData functionality until a patch is available to prevent exploitation through malicious .dxf files. Restrict access to handling .dxf files to minimize the risk of triggering the heap buffer overflow. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Integer Underflow

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-01848
CVE-2021-21897
DLA-3046-1
OPENSUSE-SU-2022_0134-1
OPENSUSE-SU-2024:10730-1

Affected Products

Debian
Suse
Dxflib