PT-2026-43187 · Gnu · Libredwg
CVSS v3.1
3.3
Low
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
GNU LibreDWG versions prior to 0.15
Description
A weakness in the Dwgbmp Utility component allows an out-of-bounds read, which occurs when the system reads data outside the intended boundary of a buffer. This issue is located in the
read 2004 compressed section() function within the src/decode.c file. Exploitation requires local access.Recommendations
Apply patch 8f03865f37f5d4ffd616fef802acc980be54d300 to resolve the issue.
As a temporary workaround, restrict access to the
read 2004 compressed section() function to minimize the risk of exploitation.Exploit
Fix
Out of bounds Read
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Libredwg