cbcvebase.
CVE-2023-26157
published 2024-01-02

CVE-2023-26157: Versions of the package libredwg before 0.12.5.6384 are vulnerable to Denial of Service (DoS) due to an out-of-bounds read involving section->num_pages in…

PriorityP335high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.54%
41.8th percentile
Versions of the package libredwg before 0.12.5.6384 are vulnerable to Denial of Service (DoS) due to an out-of-bounds read involving section->num_pages in decode_r2007.c.

Affected

1 ranges
VendorProductVersion rangeFixed in
gnulibredwg< 0.12.5.63840.12.5.6384
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.