Bug 1190688 - (CVE-2021-39530) VUL-1: CVE-2021-39530: libredwg: heap-based buffer overflow in function bit_wcs2nlen()
(CVE-2021-39530)
VUL-1: CVE-2021-39530: libredwg: heap-based buffer overflow in function bit_w...
Status: RESOLVED FIXED
Classification: openSUSE
Product: openSUSE Distribution
Classification: openSUSE
Component: Security
Leap 42.3
Other Other
: P4 - Low : Minor (vote)
: ---
Assigned To: Security Team bot
Security Team bot
https://smash.suse.de/issue/310512/
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2021-09-21 06:27 UTC by Alexander Bergmann
Modified: 2023-01-18 15:38 UTC (History)
2 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Alexander Bergmann 2021-09-21 06:27:06 UTC
CVE-2021-39530

An issue was discovered in libredwg through v0.10.1.3751. bit_wcs2nlen() in
bits.c has a heap-based buffer overflow.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2021-39530
https://github.com/LibreDWG/libredwg/issues/258
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-39530
Comment 1 Chenzi Cao 2021-09-27 10:17:52 UTC
Hi Alexander, would you please confirm that is this bug report opened for Leap42.3? It had been out of officially support. If selecting a wrong version, would you please kindly help to correct it? Thanks.
Comment 2 Alexander Bergmann 2023-01-18 15:38:08 UTC
All openSUSE versions are fixed.

openSUSE:Backports:SLE-15-SP5         0.12.5
openSUSE:Backports:SLE-15-SP4:Update  0.12.5
openSUSE:Factory                      0.12.5


Closing bug.