cbcvebase.
CVE-2021-21897
published 2021-09-08

CVE-2021-21897: A code execution vulnerability exists in the DL_Dxf::handleLWPolylineData functionality of Ribbonsoft dxflib 3.17.0. A specially-crafted .dxf file can lead to…

PriorityP346high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
2.89%
85.3th percentile
A code execution vulnerability exists in the DL_Dxf::handleLWPolylineData functionality of Ribbonsoft dxflib 3.17.0. A specially-crafted .dxf file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.

Affected

14 ranges
VendorProductVersion rangeFixed in
debiancloudcompare< cloudcompare 2.11.3-7.1 (bookworm)cloudcompare 2.11.3-7.1 (bookworm)
debiandebian_linux
debiandxflib< cloudcompare 2.11.3-7.1 (bookworm)cloudcompare 2.11.3-7.1 (bookworm)
debianhorizon-eda< cloudcompare 2.11.3-7.1 (bookworm)cloudcompare 2.11.3-7.1 (bookworm)
debianlibrecad< cloudcompare 2.11.3-7.1 (bookworm)cloudcompare 2.11.3-7.1 (bookworm)
fedoraprojectextra_packages_for_enterprise_linux
fedoraprojectextra_packages_for_enterprise_linux
fedoraprojectfedora
fedoraprojectfedora
fedoraprojectfedora
ribbonsoftdxflib
ribbonsoftdxflib>= 0 < 3.26.4-13.26.4-1
ribbonsoftdxflib>= 0 < 3.26.4-13.26.4-1
ribbonsoftdxflib>= 0 < 3.26.4-13.26.4-1

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.8HIGH
vendor_debian8.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.