openSUSE-SU-2022:10002-1
Dashboard / Vulnerabilities / openSUSE-SU-2022:10002-1
openSUSE-SU-2022:10002-1
Summary: Security update for librecad
Details: This update for librecad fixes the following issues: - CVE-2021-45341: Fixed a buffer overflow vulnerability in LibreCAD allows an attacker to achieve remote code execution via a crafted JWW document [boo#1195105] - CVE-2021-45342: Fixed a buffer overflow vulnerability in jwwlib in LibreCAD allows an attacker to achieve remote code execution via a crafted JWW document [boo#1195122] - Strip excess blank fields from librecad.desktop:MimeType [boo#1197664] Update to 2.2.0-rc3 * major release * DWG imports are more reliable now * and a lot more of bugfixes and improvements
References: https://lists.opensuse.org/archives/list/[email protected]/thread/6KTACJSABEKBQTYYPFKDEOPJ4JOG4FBE/, https://bugzilla.suse.com/1195105, https://bugzilla.suse.com/1195122, https://bugzilla.suse.com/1197664, https://www.suse.com/security/cve/CVE-2021-45341, https://www.suse.com/security/cve/CVE-2021-45342
Affected packages
Package
Name: libdxfrw
Purl: pkg:rpm/suse/libdxfrw&distro=SUSE%20Package%20Hub%2015%20SP4
Affected ranges
Type: ECOSYSTEM
Events:
