Bugzilla – Bug 1202553
VUL-1: CVE-2022-35164: libredwg: Heap use-after-free via bit_copy_chain
Last modified: 2022-08-19 18:40:03 UTC
CVE-2022-35164 LibreDWG v0.12.4.4608 & commit f2dea29 was discovered to contain a heap use-after-free via bit_copy_chain. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-35164 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-35164 https://github.com/LibreDWG/libredwg/issues/497
Affected: - openSUSE:Backports:SLE-15-SP3/libredwg 0.11.1 - openSUSE:Backports:SLE-15-SP4/libredwg 0.11.1 - openSUSE:Factory/libredwg 0.12.5
This is an autogenerated message for OBS integration: This bug (1202553) was mentioned in https://build.opensuse.org/request/show/998213 Factory / libredwg