GHSA-q6j5-wxg6-4vrvLowCVSS 3.3
A security flaw has been discovered in GNU LibreDWG up to 0.14. This impacts the function...
🔗 CVE IDs covered (1)
📋 Description
A security flaw has been discovered in GNU LibreDWG up to 0.14. This impacts the function dwg_next_entity of the file src/decode.c of the component DWG File Handler. The manipulation results in null pointer dereference. The attack must be initiated from a local position. The exploit has been released to the public and may be used for attacks. The patch is identified as 8f03865f37f5d4ffd616fef802acc980be54d300. Upgrading the affected component is advised.
🔗 References (9)
- https://nvd.nist.gov/vuln/detail/CVE-2026-9503
- https://github.com/LibreDWG/libredwg/issues/1245
- https://github.com/LibreDWG/libredwg/commit/8f03865f37f5d4ffd616fef802acc980be54d300
- https://github.com/HackC0der/CVE-Repos/blob/main/libredwg/libredwg_6d6a339_heap_oob_write_read_2004_compressed_section.dwg
- https://vuldb.com/submit/814260
- https://vuldb.com/vuln/365485
- https://vuldb.com/vuln/365485/cti
- https://www.gnu.org
- https://github.com/advisories/GHSA-q6j5-wxg6-4vrv