Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-21897

Опубликовано: 08 сент. 2021
Источник: debian

Описание

A code execution vulnerability exists in the DL_Dxf::handleLWPolylineData functionality of Ribbonsoft dxflib 3.17.0. A specially-crafted .dxf file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
cloudcomparefixed2.11.3-7.1package
cloudcompareno-dsabullseyepackage
cloudcompareno-dsabusterpackage
dxflibfixed3.26.4-1package
dxflibno-dsabullseyepackage
dxflibno-dsabusterpackage
dxflibno-dsastretchpackage
horizon-edaunfixedpackage
librecadunfixedpackage

Примечания

  • https://talosintelligence.com/vulnerability_reports/TALOS-2021-1346

  • https://github.com/qcad/qcad/commit/1eeffc5daf5a06cf6213ffc19e95923cdebb2eb8

Связанные уязвимости

CVSS3: 8.8
ubuntu
больше 4 лет назад

A code execution vulnerability exists in the DL_Dxf::handleLWPolylineData functionality of Ribbonsoft dxflib 3.17.0. A specially-crafted .dxf file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.

CVSS3: 8.8
nvd
больше 4 лет назад

A code execution vulnerability exists in the DL_Dxf::handleLWPolylineData functionality of Ribbonsoft dxflib 3.17.0. A specially-crafted .dxf file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.

CVSS3: 8.8
github
больше 3 лет назад

A code execution vulnerability exists in the DL_Dxf::handleLWPolylineData functionality of Ribbonsoft dxflib 3.17.0. A specially-crafted .dxf file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.

CVSS3: 8.8
fstec
больше 4 лет назад

Уязвимость функционала DL_Dxf::handleLWPolylineData библиотеки парсинга DXF файлов Dxflib, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании