PT-2026-43186 · Gnu · Libredwg
CVSS v3.1
3.3
Low
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
GNU LibreDWG versions prior to 0.15
Description
A security flaw exists in the Dwggrep Utility component within the
dwggrep.c file. A local attacker can cause a null pointer dereference, which occurs when a program attempts to read or write to a memory location that is null, typically leading to a crash, by manipulating the match BLOCK HEADER() function.Recommendations
Update to a version later than 0.14.
As a temporary workaround, restrict the use of the
match BLOCK HEADER() function within the Dwggrep Utility.Exploit
Fix
Improper Resource Release
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Libredwg