CVE-2021-45341
published 2022-01-25CVE-2021-45341: A buffer overflow vulnerability in CDataMoji of the jwwlib component of LibreCAD 2.2.0-rc3 and older allows an attacker to achieve Remote Code Execution using…
PriorityP354high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
6.62%
93.2th percentile
A buffer overflow vulnerability in CDataMoji of the jwwlib component of LibreCAD 2.2.0-rc3 and older allows an attacker to achieve Remote Code Execution using a crafted JWW document.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | librecad | < librecad 2.1.3-3 (bookworm) | librecad 2.1.3-3 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| librecad | librecad | < 2.2.0 | 2.2.0 |
| librecad | librecad | — | — |
| librecad | librecad | >= 0 < 2.1.3-1.3+deb11u1 | 2.1.3-1.3+deb11u1 |
| librecad | librecad | >= 0 < 2.1.3-3 | 2.1.3-3 |
| librecad | librecad | >= 0 < 2.1.3-3 | 2.1.3-3 |
| librecad | librecad | >= 0 < 2.1.3-3 | 2.1.3-3 |
| librecad | librecad | >= 0 < 2.1.3-1.2+deb10u1build0.20.04.1 | 2.1.3-1.2+deb10u1build0.20.04.1 |
| librecad | librecad | >= 0 < 2.0.9-2ubuntu0.1~esm1 | 2.0.9-2ubuntu0.1~esm1 |
| librecad | librecad | >= 0 < 2.1.2-1ubuntu0.1~esm1 | 2.1.2-1ubuntu0.1~esm1 |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv8.8HIGH
vendor_debian8.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
LibreCAD vulnerabilities
vendor_ubuntu·2023-03-15·CVSS 7.8
CVE-2021-21899 [HIGH] LibreCAD vulnerabilities
Title: LibreCAD vulnerabilities
Summary: Several security issues were fixed in LibreCAD.
Cody Sixteen discovered that LibreCAD incorrectly
handled memory when parsing DXF files. An attacker could
use this issue to cause LibreCAD to crash, leading to a
denial of service. This issue only affected
Ubuntu 16.04 ESM and Ubuntu 18.04 ESM. (CVE-2018-19105)
Lilith of Cisco Talos discovered that LibreCAD incorrectly
handled memory when parsing DWG files. An attacker could
use this issue to cause LibreCAD to crash, leading to a
denial of service, or possibly execute arbitrary code.
(CVE-2021-21898, CVE-2021-21899)
Lilith of Cisco Talos discovered that LibreCAD incorrectly
handled memory when parsing DRW files. An attacker could
use this issue to cause LibreCAD to crash, leading to a
denial of se
Debian
CVE-2021-45341: librecad - A buffer overflow vulnerability in CDataMoji of the jwwlib component of LibreCAD...
vendor_debian·2021·CVSS 8.8
CVE-2021-45341 [HIGH] CVE-2021-45341: librecad - A buffer overflow vulnerability in CDataMoji of the jwwlib component of LibreCAD...
A buffer overflow vulnerability in CDataMoji of the jwwlib component of LibreCAD 2.2.0-rc3 and older allows an attacker to achieve Remote Code Execution using a crafted JWW document.
Scope: local
bookworm: resolved (fixed in 2.1.3-3)
bullseye: resolved (fixed in 2.1.3-1.3+deb11u1)
forky: resolved (fixed in 2.1.3-3)
sid: resolved (fixed in 2.1.3-3)
trixie: resolved (fixed in 2.1.3-3)
OSV
librecad vulnerabilities
osv·2023-03-15·CVSS 7.8
CVE-2018-19105 [HIGH] librecad vulnerabilities
librecad vulnerabilities
Cody Sixteen discovered that LibreCAD incorrectly
handled memory when parsing DXF files. An attacker could
use this issue to cause LibreCAD to crash, leading to a
denial of service. This issue only affected
Ubuntu 16.04 ESM and Ubuntu 18.04 ESM. (CVE-2018-19105)
Lilith of Cisco Talos discovered that LibreCAD incorrectly
handled memory when parsing DWG files. An attacker could
use this issue to cause LibreCAD to crash, leading to a
denial of service, or possibly execute arbitrary code.
(CVE-2021-21898, CVE-2021-21899)
Lilith of Cisco Talos discovered that LibreCAD incorrectly
handled memory when parsing DRW files. An attacker could
use this issue to cause LibreCAD to crash, leading to a
denial of service, or possibly execute arbitrary code.
(CVE-2021-21900)
Albi
GHSA
GHSA-9882-476q-39vf: A buffer overflow vulnerability in CDataMoji of the jwwlib component of LibreCAD 2
ghsa_unreviewed·2022-02-15
CVE-2021-45341 [HIGH] CWE-120 GHSA-9882-476q-39vf: A buffer overflow vulnerability in CDataMoji of the jwwlib component of LibreCAD 2
A buffer overflow vulnerability in CDataMoji of the jwwlib component of LibreCAD 2.2.0-rc3 and older allows an attacker to achieve Remote Code Execution using a crafted JWW document.
OSV
CVE-2021-45341: A buffer overflow vulnerability in CDataMoji of the jwwlib component of LibreCAD 2
osv·2022-01-25·CVSS 8.8
CVE-2021-45341 [HIGH] CVE-2021-45341: A buffer overflow vulnerability in CDataMoji of the jwwlib component of LibreCAD 2
A buffer overflow vulnerability in CDataMoji of the jwwlib component of LibreCAD 2.2.0-rc3 and older allows an attacker to achieve Remote Code Execution using a crafted JWW document.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/LibreCAD/LibreCAD/issues/1462https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FCC2FZ6HZOIK3775K4MTCOUHX6PLGPEL/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VUMH3CWGVSMR2UIZEA35Q5UB7PDVVVYS/https://security.gentoo.org/glsa/202305-26https://www.debian.org/security/2022/dsa-5077https://github.com/LibreCAD/LibreCAD/issues/1462https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FCC2FZ6HZOIK3775K4MTCOUHX6PLGPEL/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VUMH3CWGVSMR2UIZEA35Q5UB7PDVVVYS/https://security.gentoo.org/glsa/202305-26https://www.debian.org/security/2022/dsa-5077
2022-01-25
Published