Bug 1190688 (CVE-2021-39530)

Summary: VUL-1: CVE-2021-39530: libredwg: heap-based buffer overflow in function bit_wcs2nlen()
Product: [openSUSE] openSUSE Distribution Reporter: Alexander Bergmann <abergmann>
Component: SecurityAssignee: Security Team bot <security-team>
Status: RESOLVED FIXED QA Contact: Security Team bot <security-team>
Severity: Minor    
Priority: P4 - Low CC: abergmann, chcao
Version: Leap 42.3   
Target Milestone: ---   
Hardware: Other   
OS: Other   
URL: https://smash.suse.de/issue/310512/
Whiteboard:
Found By: Security Response Team Services Priority:
Business Priority: Blocker: ---
Marketing QA Status: --- IT Deployment: ---

Description Alexander Bergmann 2021-09-21 06:27:06 UTC
CVE-2021-39530

An issue was discovered in libredwg through v0.10.1.3751. bit_wcs2nlen() in
bits.c has a heap-based buffer overflow.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2021-39530
https://github.com/LibreDWG/libredwg/issues/258
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-39530
Comment 1 Chenzi Cao 2021-09-27 10:17:52 UTC
Hi Alexander, would you please confirm that is this bug report opened for Leap42.3? It had been out of officially support. If selecting a wrong version, would you please kindly help to correct it? Thanks.
Comment 2 Alexander Bergmann 2023-01-18 15:38:08 UTC
All openSUSE versions are fixed.

openSUSE:Backports:SLE-15-SP5         0.12.5
openSUSE:Backports:SLE-15-SP4:Update  0.12.5
openSUSE:Factory                      0.12.5


Closing bug.