PT-2024-12088 · Libredwg+1 · Libredwg+1

Eugene Lim

·

Published

2024-01-01

·

Updated

2024-07-26

·

CVE-2023-26157

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions libredwg versions prior to 0.12.5.6384
Description The issue is related to a Denial of Service (DoS) due to an out-of-bounds read involving section->num pages in the decode r2007.c file. This can cause the software to become unresponsive or crash.
Recommendations For versions prior to 0.12.5.6384, update to version 0.12.5.6384 or later to resolve the issue. As a temporary workaround, consider restricting access to the decode r2007.c file or disabling the functionality that involves the section->num pages variable until a patch is available.

Exploit

Fix

DoS

Out of bounds Read

Resource Exhaustion

Weakness Enumeration

Related Identifiers

ALT-PU-2024-10169
ALT-PU-2024-6594
CVE-2023-26157
OPENSUSE-SU-2024:0147-1
OPENSUSE-SU-2024:13544-1

Affected Products

Alt Linux
Libredwg