librecad 2.1.3-1.2+deb10u1 source package in Debian

Changelog

librecad (2.1.3-1.2+deb10u1) buster-security; urgency=high

  * Non-maintainer upload by the Security Team.
  * CVE-2021-21898: A code execution vulnerability exists in the
    dwgCompressor::decompress18() functionality of LibreCad libdxfrw. A
    specially-crafted .dwg file can lead to an out-of-bounds write.
  * CVE-2021-21899: A code execution vulnerability exists in the
    dwgCompressor::copyCompBytes21 functionality of LibreCad libdxfrw. A
    specially-crafted .dwg file can lead to a heap buffer overflow.
  * CVE-2021-21900: A code execution vulnerability exists in the
    dxfRW::processLType() functionality of LibreCad libdxfrw. A
    specially-crafted .dxf file can lead to a use-after-free
    vulnerability.
  * CVE-2021-45341: Buffer overflow vulnerabilities in CDataMoji of the jwwlib
    component of LibreCAD allows an attacker to achieve Remote Code Execution
    using a crafted JWW document.
  * CVE-2021-45342: Buffer overflow vulnerabilities in CDataList of the jwwlib
    component of LibreCAD allows an attacker to achieve Remote Code Execution
    using a crafted JWW document.
  * CVE-2021-45343: a NULL pointer dereference in the HATCH handling of
    libdxfrw allows an attacker to crash the application using a crafted DXF
    document.

 -- Aron Xu <email address hidden>  Sun, 30 Jan 2022 22:53:52 +0800

Upload details

Uploaded by:
Debian Science Team
Uploaded to:
Buster
Original maintainer:
Debian Science Team
Architectures:
any all
Section:
graphics
Urgency:
Very Urgent

See full publishing history Publishing

Series Pocket Published Component Section
Buster release main graphics

Builds

Downloads

File Size SHA-256 Checksum
librecad_2.1.3-1.2+deb10u1.dsc 2.2 KiB 9b1744f40ed019288984ef5e3f6238b260c48f85896c69351ce0658870786b17
librecad_2.1.3.orig.tar.gz 21.4 MiB 74c4ede409b13d0365c65c0cd52dba04f1049530f6df706dc905443d5e60db06
librecad_2.1.3-1.2+deb10u1.debian.tar.xz 17.8 KiB 09f3a2ebf05448c0a6ff0f7fec1c7c65e8eba1e6b9cf71002aa964ae7c89a79d

No changes file available.

Binary packages built by this source