Bugzilla – Bug 1199863
VUL-0: CVE-2021-42585: libredwg: Heap buffer overflow in dwgread via crafted dwg file
Last modified: 2022-05-24 09:02:21 UTC
CVE-2021-42585 A heap buffer overflow was discovered in copy_compressed_bytes in decode_r2007.c in dwgread before 0.12.4 via a crafted dwg file. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2021-42585 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-42585 https://github.com/LibreDWG/libredwg/issues/351
Affected: - openSUSE:Backports:SLE-15-SP3 - openSUSE:Backports:SLE-15-SP4 Factory already fixed. Fix: https://github.com/LibreDWG/libredwg/commit/ecf5183d8b3b286afe2a30021353b7116e0208dd
see submissions openSUSE:Maintenance:17493 libredwg.openSUSE_Backports_SLE-15-SP3_Update openSUSE:Maintenance:17501 libredwg.openSUSE_Backports_SLE-15-SP4_Update