CVE-2019-20009Allocation of Resources Without Limits or Throttling in Libredwg

Severity
6.5MEDIUMNVD
EPSS
0.6%
top 31.83%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 27
Latest updateMay 24

Description

An issue was discovered in GNU LibreDWG before 0.93. Crafted input will lead to an attempted excessive memory allocation in dwg_decode_SPLINE_private in dwg.spec.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6

Affected Packages3 packages

NVDgnu/libredwg< 0.9.3
NVDopensuse/leap15.1

Patches

🔴Vulnerability Details

2
GHSA
GHSA-8cg9-cgp6-9vw3: An issue was discovered in GNU LibreDWG before 02022-05-24
CVEList
CVE-2019-20009: An issue was discovered in GNU LibreDWG before 02019-12-27
CVE-2019-20009 — GNU Libredwg vulnerability | cvebase