MGASA-2022-0151
Dashboard / Vulnerabilities / MGASA-2022-0151
MGASA-2022-0151
Summary: Updated libdxfrw packages fix security vulnerability
Details: A code execution vulnerability exists in the dwgCompressor::decompress18() functionality of LibreCad libdxfrw 2.2.0-rc2-19-ge02f3580. A specially-crafted .dwg file can lead to an out-of-bounds write. An attacker can provide a malicious file to trigger this vulnerability. (CVE-2021-21898) A code execution vulnerability exists in the dwgCompressor::copyCompBytes21 functionality of LibreCad libdxfrw 2.2.0-rc2-19-ge02f3580. A specially-crafted .dwg file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability. (CVE-2021-21899) A code execution vulnerability exists in the dxfRW::processLType() functionality of LibreCad libdxfrw 2.2.0-rc2-19-ge02f3580. A specially-crafted .dxf file can lead to a use-after-free vulnerability. An attacker can provide a malicious file to trigger this vulnerability. (CVE-2021-21900) In LibreCAD 2.2.0, a NULL pointer dereference in the HATCH handling of libdxfrw allows an attacker to crash the application using a crafted DXF document. (CVE-2021-45343)
References: https://advisories.mageia.org/MGASA-2022-0151.html, https://bugs.mageia.org/show_bug.cgi?id=29720, https://lists.fedoraproject.org/archives/list/[email protected]/thread/RDI3HCTCACMIC7I4ILB3NRU6DCMADI5H/, https://www.debian.org/lts/security/2021/dla-2838, https://lists.fedoraproject.org/archives/list/[email protected]/thread/VUMH3CWGVSMR2UIZEA35Q5UB7PDVVVYS/, https://lists.opensuse.org/archives/list/[email protected]/thread/6TWLTKRSHNPCLQL7UXQSITHNYJT5XSK5/
Affected packages
Package
Name: libdxfrw
Purl: pkg:rpm/mageia/libdxfrw?arch=source&distro=mageia-8
Affected ranges
Type: ECOSYSTEM
Events:
