CVE-2021-21897HIGHCVSS 8.8fixed in cloudcompare 2.11.3-7.1 (bookworm)2021
CVE-2021-21897 [HIGH] CVE-2021-21897: cloudcompare - A code execution vulnerability exists in the DL_Dxf::handleLWPolylineData functi...
A code execution vulnerability exists in the DL_Dxf::handleLWPolylineData functionality of Ribbonsoft dxflib 3.17.0. A specially-crafted .dxf file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.
Scope: local
bookworm: resolved (fixed in 2.11.3-7.1)
bullseye: open
forky: resolved (fixed in 2.11.3-7.1)
s
debian