Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fgx7-4whx-rx6p

Опубликовано: 09 июл. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 1.9
CVSS3: 3.3

Описание

A vulnerability was found in GNU LibreDWG up to 0.13.4. The impacted element is the function dwg_next_entity of the file src/dwg.c of the component DWG File Handler. Performing a manipulation of the argument next_obj results in null pointer dereference. The attack must be initiated from a local position. The exploit has been made public and could be used. Upgrading to version 0.14 is sufficient to resolve this issue. The patch is named dde45dac3c4d902e4d8fed150a8017b9732019c9. Upgrading the affected component is recommended. Different than CVE-2026-9503.

A vulnerability was found in GNU LibreDWG up to 0.13.4. The impacted element is the function dwg_next_entity of the file src/dwg.c of the component DWG File Handler. Performing a manipulation of the argument next_obj results in null pointer dereference. The attack must be initiated from a local position. The exploit has been made public and could be used. Upgrading to version 0.14 is sufficient to resolve this issue. The patch is named dde45dac3c4d902e4d8fed150a8017b9732019c9. Upgrading the affected component is recommended. Different than CVE-2026-9503.

EPSS

Процентиль: 2%
0.00118
Низкий

1.9 Low

CVSS4

3.3 Low

CVSS3

Дефекты

CWE-404

Связанные уязвимости

CVSS3: 3.3
nvd
23 дня назад

A vulnerability was found in GNU LibreDWG up to 0.13.4. The impacted element is the function dwg_next_entity of the file src/dwg.c of the component DWG File Handler. Performing a manipulation of the argument next_obj results in null pointer dereference. The attack must be initiated from a local position. The exploit has been made public and could be used. Upgrading to version 0.14 is sufficient to resolve this issue. The patch is named dde45dac3c4d902e4d8fed150a8017b9732019c9. Upgrading the affected component is recommended. Different than CVE-2026-9503.

CVSS3: 3.3
debian
23 дня назад

A vulnerability was found in GNU LibreDWG up to 0.13.4. The impacted e ...

CVSS3: 3.3
fstec
3 месяца назад

Уязвимость функции dwg_next_entity() файла src/dwg.c библиотеки для обработки файлов формата DWG LibreDWG, позволяющая нарушителю вызвать отказ в обслуживании

suse-cvrf
19 дней назад

Security update for libredwg

EPSS

Процентиль: 2%
0.00118
Низкий

1.9 Low

CVSS4

3.3 Low

CVSS3

Дефекты

CWE-404