Bug 1190345 - (CVE-2021-21897) VUL-1: CVE-2021-21897: dfxlib: heap-based buffer overflow in the DL_Dxf:handleLWPolylineData function
(CVE-2021-21897)
VUL-1: CVE-2021-21897: dfxlib: heap-based buffer overflow in the DL_Dxf:handl...
Status: RESOLVED FIXED
Classification: openSUSE
Product: openSUSE Distribution
Classification: openSUSE
Component: Security
Leap 15.3
Other Other
: P4 - Low : Normal (vote)
: ---
Assigned To: Security Team bot
Security Team bot
https://smash.suse.de/issue/309347/
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2021-09-09 13:48 UTC by Gabriele Sonnu
Modified: 2022-09-13 07:16 UTC (History)
1 user (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Gabriele Sonnu 2021-09-09 13:48:18 UTC
A code execution vulnerability exists in the DL_Dxf::handleLWPolylineData
functionality of Ribbonsoft dxflib 3.17.0. A specially-crafted .dxf file can
lead to a heap buffer overflow. An attacker can provide a malicious file to
trigger this vulnerability.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2021-21897
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-21897
https://talosintelligence.com/vulnerability_reports/TALOS-2021-1346
Comment 1 Gabriele Sonnu 2021-09-09 13:49:38 UTC
Affected packages:

- openSUSE:Backports:SLE-15-SP2/dxflib  3.17.0
- openSUSE:Backports:SLE-15-SP3/dxflib  3.17.0
- openSUSE:Backports:SLE-15-SP4/dxflib  3.17.0
- openSUSE:Factory/dxflib               3.17.0

Upstream patch:

https://github.com/qcad/qcad/commit/1eeffc5daf5a06cf6213ffc19e95923cdebb2eb8
Comment 2 Jan Engelhardt 2021-09-20 10:09:26 UTC
Since SLE has this layered repo approach, where best to submit?
openSUSE:Backports:SLE-15-SP2:Update, or SP3 Update, or all three (SP2,SP3,SP4)?
Comment 4 Jan Engelhardt 2022-05-16 20:00:01 UTC
rq 977597 977598
Comment 5 OBSbugzilla Bot 2022-05-16 20:40:04 UTC
This is an autogenerated message for OBS integration:
This bug (1190345) was mentioned in
https://build.opensuse.org/request/show/977597 Backports:SLE-15-SP3 / dxflib
https://build.opensuse.org/request/show/977598 Backports:SLE-15-SP4 / dxflib
Comment 6 Swamp Workflow Management 2022-05-17 19:19:02 UTC
openSUSE-SU-2022:0134-1: An update that fixes three vulnerabilities is now available.

Category: security (important)
Bug References: 1190345,1193907,1193913
CVE References: CVE-2021-21897,CVE-2021-33430,CVE-2021-41496
JIRA References: 
Sources used:
openSUSE Leap 15.3 (src):    python-numpy-1.17.3-10.1, python-numpy_1_17_3-gnu-hpc-1.17.3-10.1
openSUSE Backports SLE-15-SP3 (src):    dxflib-3.17.0-bp153.2.3.1
Comment 7 Gabriele Sonnu 2022-09-13 07:16:58 UTC
Done.