MEDIUM
An issue was discovered in GNU LibreDWG before 0.93
Published Dec 27, 2019
6.5
MEDIUMCVSS 3.1
EPSS 1.37%
Description
An issue was discovered in GNU LibreDWG before 0.93. Crafted input will lead to an attempted excessive memory allocation in decode_3dsolid in dwg.spec.
Affected products
Remediation
No remediation recorded yet.
Weaknesses (1)
References (5)
- http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00033.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00045.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- https://github.com/LibreDWG/libredwg/compare/0.9.2...0.9.3 x_refsource_MISCPatchRelease NotesThird Party Advisory
- https://github.com/LibreDWG/libredwg/issues/176 x_refsource_MISCExploitIssue TrackingThird Party Advisory
- https://github.com/LibreDWG/libredwg/issues/176#issuecomment-568643060 x_refsource_MISCExploitIssue TrackingThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00033.html | vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory | |
| http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00045.html | vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory | |
| https://github.com/LibreDWG/libredwg/compare/0.9.2...0.9.3 | x_refsource_MISCPatchRelease NotesThird Party Advisory | |
| https://github.com/LibreDWG/libredwg/issues/176 | x_refsource_MISCExploitIssue TrackingThird Party Advisory | |
| https://github.com/LibreDWG/libredwg/issues/176#issuecomment-568643060 | x_refsource_MISCExploitIssue TrackingThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Dec 27, 2019
Updated Aug 5, 2024
Reserved Dec 27, 2019
Link CVE-2019-20013
CISA Vulnrichment
Updated n/a