Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3h8r-9w82-hxmh

Опубликовано: 09 июл. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 1.9
CVSS3: 5.3

Описание

A vulnerability has been found in GNU LibreDWG up to 0.13.4. The affected element is the function dwg_bmp of the file src/dwg.c of the component BMP Image Handler. Such manipulation leads to heap-based buffer overflow. The attack must be carried out locally. The exploit has been disclosed to the public and may be used. Upgrading to version 0.14 is sufficient to fix this issue. The name of the patch is 18fd542bb4d5ccedf9de12052bf50068b2b26f06. It is suggested to upgrade the affected component.

A vulnerability has been found in GNU LibreDWG up to 0.13.4. The affected element is the function dwg_bmp of the file src/dwg.c of the component BMP Image Handler. Such manipulation leads to heap-based buffer overflow. The attack must be carried out locally. The exploit has been disclosed to the public and may be used. Upgrading to version 0.14 is sufficient to fix this issue. The name of the patch is 18fd542bb4d5ccedf9de12052bf50068b2b26f06. It is suggested to upgrade the affected component.

EPSS

Процентиль: 3%
0.00133
Низкий

1.9 Low

CVSS4

5.3 Medium

CVSS3

Дефекты

CWE-119

Связанные уязвимости

CVSS3: 5.3
nvd
24 дня назад

A vulnerability has been found in GNU LibreDWG up to 0.13.4. The affected element is the function dwg_bmp of the file src/dwg.c of the component BMP Image Handler. Such manipulation leads to heap-based buffer overflow. The attack must be carried out locally. The exploit has been disclosed to the public and may be used. Upgrading to version 0.14 is sufficient to fix this issue. The name of the patch is 18fd542bb4d5ccedf9de12052bf50068b2b26f06. It is suggested to upgrade the affected component.

CVSS3: 5.3
debian
24 дня назад

A vulnerability has been found in GNU LibreDWG up to 0.13.4. The affec ...

CVSS3: 5.3
fstec
25 дней назад

Уязвимость функции dwg_bmp компонента src/dwg.c библиотеки для обработки файлов формата DWG LibreDWG, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 3%
0.00133
Низкий

1.9 Low

CVSS4

5.3 Medium

CVSS3

Дефекты

CWE-119