漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
GNU LibreDWG R2004 Section Decompression decode.c decompress_R2004_section heap-based overflow
Vulnerability Description
A vulnerability was determined in GNU LibreDWG 0.13.4-154-g0b573035. This impacts the function decompress_R2004_section of the file src/decode.c of the component R2004 Section Decompression. Executing a manipulation can lead to heap-based buffer overflow. The attack requires local access. The exploit has been publicly disclosed and may be utilized. Upgrading to version 0.14.8396 will fix this issue. This patch is called 3d0f9fc2eddbd6579c99af3111c37c98f03475d0. You should upgrade the affected component.
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Vulnerability Type
堆缓冲区溢出
Vulnerability Title
GNU LibreDWG 缓冲区错误漏洞
Vulnerability Description
GNU libredwg是美国GNU基金会开源的一个DWG文件格式实现。 GNU LibreDWG 0.13.4-154-g0b573035版本存在缓冲区错误漏洞,该漏洞源于R2004 Section Decompression组件中的decompress_R2004_section函数存在堆缓冲区溢出,可能导致攻击者进行操纵。
CVSS Information
N/A
Vulnerability Type
N/A