Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9fj3-rp2j-9wq6

Опубликовано: 27 мая 2026
Источник: github
Github: Не прошло ревью
CVSS4: 5.5
CVSS3: 7.3

Описание

A flaw has been found in GNU libredwg up to 0.13.4.8160. This issue affects the function bit_read_RC of the file bits.c of the component Dwgbmp Utility. This manipulation causes heap-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been published and may be used. Patch name: 8f03865f37f5d4ffd616fef802acc980be54d300. Applying a patch is the recommended action to fix this issue.

A flaw has been found in GNU libredwg up to 0.13.4.8160. This issue affects the function bit_read_RC of the file bits.c of the component Dwgbmp Utility. This manipulation causes heap-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been published and may be used. Patch name: 8f03865f37f5d4ffd616fef802acc980be54d300. Applying a patch is the recommended action to fix this issue.

EPSS

Процентиль: 27%
0.00339
Низкий

5.5 Medium

CVSS4

7.3 High

CVSS3

Дефекты

CWE-119

Связанные уязвимости

CVSS3: 7.3
nvd
2 месяца назад

A flaw has been found in GNU libredwg up to 0.13.4.8160. This issue affects the function bit_read_RC of the file bits.c of the component Dwgbmp Utility. This manipulation causes heap-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been published and may be used. Patch name: 8f03865f37f5d4ffd616fef802acc980be54d300. Applying a patch is the recommended action to fix this issue.

CVSS3: 7.3
debian
2 месяца назад

A flaw has been found in GNU libredwg up to 0.13.4.8160. This issue af ...

CVSS3: 7.3
fstec
3 месяца назад

Уязвимость функции bit_read_RC() компонента Dwgbmp Utility библиотеки для обработки файлов формата DWG LibreDWG, позволяющая нарушителю вызвать отказ в обслуживании

suse-cvrf
19 дней назад

Security update for libredwg

EPSS

Процентиль: 27%
0.00339
Низкий

5.5 Medium

CVSS4

7.3 High

CVSS3

Дефекты

CWE-119