UBUNTU-CVE-2021-21898
Dashboard / Vulnerabilities / UBUNTU-CVE-2021-21898
UBUNTU-CVE-2021-21898
Summary:
Details: A code execution vulnerability exists in the dwgCompressor::decompress18() functionality of LibreCad libdxfrw 2.2.0-rc2-19-ge02f3580. A specially-crafted .dwg file can lead to an out-of-bounds write. An attacker can provide a malicious file to trigger this vulnerability.
References: https://ubuntu.com/security/CVE-2021-21898, https://talosintelligence.com/vulnerability_reports/TALOS-2021-1349, https://github.com/LibreCAD/libdxfrw/commit/ba3fa95648bef948e008dfbdd31a4d21badd71f0, https://ubuntu.com/security/notices/USN-5957-1, https://www.cve.org/CVERecord?id=CVE-2021-21898
Affected packages
Package
Name: librecad
Purl: pkg:deb/ubuntu/[email protected]~esm1?arch=source&distro=esm-apps/xenial
Affected ranges
Type: ECOSYSTEM
Events:
