MEDIUM
An issue was discovered in GNU LibreDWG 0.92
Published Dec 27, 2019
6.5
MEDIUMCVSS 3.1
EPSS 1.36%
Description
An issue was discovered in GNU LibreDWG 0.92. Crafted input will lead to an attempted excessive memory allocation in dwg_decode_HATCH_private in dwg.spec.
Affected products
Remediation
No remediation recorded yet.
Weaknesses (1)
References (5)
- http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00033.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00045.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-10568 Advisory
- https://github.com/LibreDWG/libredwg/issues/176 x_refsource_MISCExploitIssue TrackingThird Party Advisory
- https://github.com/LibreDWG/libredwg/issues/176#issuecomment-568643088 x_refsource_MISCExploitIssue TrackingThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00033.html | vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory | |
| http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00045.html | vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-10568 | Advisory | |
| https://github.com/LibreDWG/libredwg/issues/176 | x_refsource_MISCExploitIssue TrackingThird Party Advisory | |
| https://github.com/LibreDWG/libredwg/issues/176#issuecomment-568643088 | x_refsource_MISCExploitIssue TrackingThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Dec 27, 2019
Updated Aug 5, 2024
Reserved Dec 27, 2019
Link CVE-2019-20012
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2019-10568 Assigner mitre
Published Dec 27, 2019
Updated Aug 5, 2024
Exploited since n/a
Link EUVD-2019-10568