UBUNTU-CVE-2021-21899
Dashboard / Vulnerabilities / UBUNTU-CVE-2021-21899
UBUNTU-CVE-2021-21899
Summary:
Details: A code execution vulnerability exists in the dwgCompressor::copyCompBytes21 functionality of LibreCad libdxfrw 2.2.0-rc2-19-ge02f3580. A specially-crafted .dwg file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.
References: https://ubuntu.com/security/CVE-2021-21899, https://talosintelligence.com/vulnerability_reports/TALOS-2021-1350, https://github.com/LibreCAD/libdxfrw/commit/6417118874333309aa10c4e59f954c3905a6e8b5, https://ubuntu.com/security/notices/USN-5957-1, https://www.cve.org/CVERecord?id=CVE-2021-21899
Affected packages
Package
Name: librecad
Purl: pkg:deb/ubuntu/[email protected]~esm1?arch=source&distro=esm-apps/xenial
Affected ranges
Type: ECOSYSTEM
Events:
