LibreDWG v0.11 to v0.12.5 was discovered to contain a heap buffer overflow via the function bit_write_TF at bits.c.
The product writes data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://github.com/LibreDWG/libredwg/issues/677#BUG2 | third party advisory issue tracking exploit |
https://github.com/LibreDWG/libredwg/commit/8651fa27dd2de731e706e2ba09f0d28e4e0dce33 | patch |
https://github.com/LibreDWG/libredwg/blob/0.11/src/out_dxf.c#L1792 | product |