Bugzilla – Bug 1186168
VUL-1: CVE-2020-21836: libredwg: heap based buffer overflow vulnerability exists via read_2004_section_preview ../../src/decode.c:3175.
Last modified: 2021-05-18 07:36:46 UTC
CVE-2020-21836 A heap based buffer overflow vulnerability exists in GNU LibreDWG 0.10 via read_2004_section_preview ../../src/decode.c:3175. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2020-21836 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-21836 https://github.com/LibreDWG/libredwg/issues/188#issuecomment-574493437 http://gnu.com
fixed in Factory and Leap, closing