CVE-2021-21897
published 2021-09-08CVE-2021-21897: A code execution vulnerability exists in the DL_Dxf::handleLWPolylineData functionality of Ribbonsoft dxflib 3.17.0. A specially-crafted .dxf file can lead to…
PriorityP346high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
2.89%
85.3th percentile
A code execution vulnerability exists in the DL_Dxf::handleLWPolylineData functionality of Ribbonsoft dxflib 3.17.0. A specially-crafted .dxf file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | cloudcompare | < cloudcompare 2.11.3-7.1 (bookworm) | cloudcompare 2.11.3-7.1 (bookworm) |
| debian | debian_linux | — | — |
| debian | dxflib | < cloudcompare 2.11.3-7.1 (bookworm) | cloudcompare 2.11.3-7.1 (bookworm) |
| debian | horizon-eda | < cloudcompare 2.11.3-7.1 (bookworm) | cloudcompare 2.11.3-7.1 (bookworm) |
| debian | librecad | < cloudcompare 2.11.3-7.1 (bookworm) | cloudcompare 2.11.3-7.1 (bookworm) |
| fedoraproject | extra_packages_for_enterprise_linux | — | — |
| fedoraproject | extra_packages_for_enterprise_linux | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| ribbonsoft | dxflib | — | — |
| ribbonsoft | dxflib | >= 0 < 3.26.4-1 | 3.26.4-1 |
| ribbonsoft | dxflib | >= 0 < 3.26.4-1 | 3.26.4-1 |
| ribbonsoft | dxflib | >= 0 < 3.26.4-1 | 3.26.4-1 |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.8HIGH
vendor_debian8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-ghgg-v38h-7v7m: A code execution vulnerability exists in the DL_Dxf::handleLWPolylineData functionality of Ribbonsoft dxflib 3
ghsa_unreviewed·2022-05-24
CVE-2021-21897 [HIGH] CWE-191 GHSA-ghgg-v38h-7v7m: A code execution vulnerability exists in the DL_Dxf::handleLWPolylineData functionality of Ribbonsoft dxflib 3
A code execution vulnerability exists in the DL_Dxf::handleLWPolylineData functionality of Ribbonsoft dxflib 3.17.0. A specially-crafted .dxf file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.
OSV
CVE-2021-21897: A code execution vulnerability exists in the DL_Dxf::handleLWPolylineData functionality of Ribbonsoft dxflib 3
osv·2021-09-08·CVSS 8.8
CVE-2021-21897 [HIGH] CVE-2021-21897: A code execution vulnerability exists in the DL_Dxf::handleLWPolylineData functionality of Ribbonsoft dxflib 3
A code execution vulnerability exists in the DL_Dxf::handleLWPolylineData functionality of Ribbonsoft dxflib 3.17.0. A specially-crafted .dxf file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.
Debian
CVE-2021-21897: cloudcompare - A code execution vulnerability exists in the DL_Dxf::handleLWPolylineData functi...
vendor_debian·2021·CVSS 8.8
CVE-2021-21897 [HIGH] CVE-2021-21897: cloudcompare - A code execution vulnerability exists in the DL_Dxf::handleLWPolylineData functi...
A code execution vulnerability exists in the DL_Dxf::handleLWPolylineData functionality of Ribbonsoft dxflib 3.17.0. A specially-crafted .dxf file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.
Scope: local
bookworm: resolved (fixed in 2.11.3-7.1)
bullseye: open
forky: resolved (fixed in 2.11.3-7.1)
sid: resolved (fixed in 2.11.3-7.1)
trixie: resolved (fixed in 2.11.3-7.1)
No detection rules found.
No public exploits indexed.
Talos
Vulnerability Spotlight: Heap buffer overflow vulnerability in Ribbonsoft dxflib library
blogs_talos·2021-09-07·CVSS 8.8
CVE-2021-21897 [HIGH] Vulnerability Spotlight: Heap buffer overflow vulnerability in Ribbonsoft dxflib library
Lilith >_> of Cisco Talos discovered this vulnerability.
Cisco Talos recently discovered an exploitable heap-based buffer overflow vulnerability in Ribbonsoft’s dxflib library that could lead to code execution.
The dxflib library is a C++ library utilized by digital design software such as QCAD and KiCad to parse DXF files for reading and writing. TALOS-2021-1346 (CVE-2021-21897) is a vulnerability that arises if an attacker were to provide the user with a specially crafted .dxf file. The attacker could cause a heap buffer overflow, which could eventually allow them to execute remote code on the victim machine.
Cisco Talos worked with Ribbonsoft to ensure that this issue is resolved and an update is available for affected customers, all in adherence to Cisco’s vulnerability disclosure p
Talos
Vulnerability Spotlight: Heap buffer overflow vulnerability in Ribbonsoft dxflib library
blogs_talos·2021-09-07·CVSS 8.8
CVE-2021-21897 [HIGH] Vulnerability Spotlight: Heap buffer overflow vulnerability in Ribbonsoft dxflib library
## Vulnerability Spotlight: Heap buffer overflow vulnerability in Ribbonsoft dxflib library
Lilith >_> of Cisco Talos discovered this vulnerability.
Cisco Talos recently discovered an exploitable heap-based buffer overflow vulnerability in Ribbonsoft’s dxflib library that could lead to code execution.
The dxflib library is a C++ library utilized by digital design software such as QCAD and KiCad to parse DXF files for reading and writing. TALOS-2021-1346 (CVE-2021-21897) is a vulnerability that arises if an attacker were to provide the user with a specially crafted .dxf file. The attacker could cause a heap buffer overflow, which could eventually allow them to execute remote code on the victim machine.
Cisco Talos worked with Ribbonsoft to ensure that this issue is resolved and an updat
https://lists.debian.org/debian-lts-announce/2022/06/msg00008.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5BUOTYU3KKIYE4BEBUFA4MRS462P3OWM/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DA4C4X5GMM65VYLUW7Q7YL6P5NDB633A/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IMGMEPTYL7WTQ333J6SMC6MUHDMMWT3O/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/L2H36XRMAPQBIOVIIFX6KUT5YOG2ETM6/https://talosintelligence.com/vulnerability_reports/TALOS-2021-1346https://lists.debian.org/debian-lts-announce/2022/06/msg00008.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5BUOTYU3KKIYE4BEBUFA4MRS462P3OWM/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DA4C4X5GMM65VYLUW7Q7YL6P5NDB633A/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IMGMEPTYL7WTQ333J6SMC6MUHDMMWT3O/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/L2H36XRMAPQBIOVIIFX6KUT5YOG2ETM6/https://talosintelligence.com/vulnerability_reports/TALOS-2021-1346
2021-09-08
Published