Bug 1190688 - (CVE-2021-39530) VUL-1: CVE-2021-39530: libredwg: heap-based buffer overflow in function bit_wcs2nlen()
VUL-1: CVE-2021-39530: libredwg: heap-based buffer overflow in function bit_w...
Status: NEW
Classification: openSUSE
Product: openSUSE Distribution
Classification: openSUSE
Component: Security
Leap 42.3
Other Other
: P4 - Low : Minor (vote)
: ---
Assigned To: Security Team bot
Security Team bot
Depends on:
  Show dependency treegraph
Reported: 2021-09-21 06:27 UTC by Alexander Bergmann
Modified: 2021-09-27 10:17 UTC (History)
2 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---
chcao: needinfo? (abergmann)


Note You need to log in before you can comment on or make changes to this bug.
Description Alexander Bergmann 2021-09-21 06:27:06 UTC

An issue was discovered in libredwg through v0.10.1.3751. bit_wcs2nlen() in
bits.c has a heap-based buffer overflow.

Comment 1 Chenzi Cao 2021-09-27 10:17:52 UTC
Hi Alexander, would you please confirm that is this bug report opened for Leap42.3? It had been out of officially support. If selecting a wrong version, would you please kindly help to correct it? Thanks.