Bugzilla – Bug 1102702
VUL-0: CVE-2018-14524: libredwg: dwg_decode_eed in decode.c leads to a double free
Last modified: 2018-10-02 17:12:51 UTC
Created attachment 778066 [details] Reproducer CVE-2018-14524 dwg_decode_eed in decode.c in GNU LibreDWG 0.5.1048 leads to a double free (in dwg_free_eed in free.c) because it does not properly manage the obj->eed value after a free occurs. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-14524 https://github.com/LibreDWG/libredwg/issues/33
submitted to factory
This is an autogenerated message for OBS integration: This bug (1102702) was mentioned in https://build.opensuse.org/request/show/628364 Factory / libredwg