PT-2022-12327 · Librecad+3 · Librecad+3

Eldstal

·

Published

2019-08-13

·

Updated

2024-06-15

·

CVE-2021-45342

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions LibreCAD versions 2.2.0-rc3 and older
Description A buffer overflow vulnerability in CDataList of the jwwlib component allows an attacker to achieve Remote Code Execution using a crafted JWW document.
Recommendations For LibreCAD versions 2.2.0-rc3 and older, consider disabling the CDataList component of the jwwlib until a patch is available to prevent Remote Code Execution attacks using crafted JWW documents. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2019-2462
ALT-PU-2019-2467
CVE-2021-45342
DLA-2908-1
DSA-5077-1
MGASA-2022-0152
OPENSUSE-SU-2022:0143-1
OPENSUSE-SU-2022:10002-1
OPENSUSE-SU-2024:12082-1
USN-5957-1

Affected Products

Alt Linux
Librecad
Linuxmint
Ubuntu