NixOS / nixpkgs

Nix Packages collection & NixOS
MIT License
18.19k stars 14.19k forks source link

Vulnerability roundup 111: librecad-2.2.0-rc2: 2 advisories [8.8] #160668

Closed ckauhaus closed 11 months ago

ckauhaus commented 2 years ago

search, files

CVE details

CVE-2021-45341

A buffer overflow vulnerability in CDataMoji of the jwwlib component of LibreCAD 2.2.0-rc3 and older allows an attacker to achieve Remote Code Execution using a crafted JWW document.

CVE-2021-45342

A buffer overflow vulnerability in CDataList of the jwwlib component of LibreCAD 2.2.0-rc3 and older allows an attacker to achieve Remote Code Execution using a crafted JWW document.


Scanned versions: nixos-21.11: 2128d0aa28e; nixos-unstable: 5aaed40d22f.

Cc @Kiwi Cc @viric

LeSuisse commented 11 months ago

Fixed in 6896348d0fad85cfa3975d729b0279537981edfb and 57e6253b8c03e3bbf95e798085ee0fcf73fa6870.