Bugzilla – Bug 1218473
VUL-0: CVE-2023-26157: libredwg: out-of-bound read involving section->num_pages in decode_r2007.c
Last modified: 2024-05-29 22:04:53 UTC
Versions of the package libredwg before 0.12.5.6384 are vulnerable to Denial of Service (DoS) due to an out-of-bounds read involving section->num_pages in decode_r2007.c. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-26157 https://github.com/LibreDWG/libredwg/issues/850 Patch: https://github.com/LibreDWG/libredwg/commit/c8cf03ce4c2315b146caf582ea061c0460193bcc
This is an autogenerated message for OBS integration: This bug (1218473) was mentioned in https://build.opensuse.org/request/show/1136185 Backports:SLE-15-SP6 / libredwg
openSUSE-SU-2024:0147-1: An update that fixes one vulnerability is now available. Category: security (important) Bug References: 1218473 CVE References: CVE-2023-26157 JIRA References: Sources used: openSUSE Backports SLE-15-SP5 (src): libredwg-0.12.5.6924-bp155.3.6.1