Alerts This Week
Warning Icon 1 560
Alerts This Week
Warning Icon 1 560

Mageia 8 MGASA-2022-0152 Critical: Librecad Remote Execution Risk

mageia
Calendar Grey April 24, 2022
Dist Mageia Esm H88
Recent updates to librecad packages tackle buffer overflow vulnerabilities that could permit remote code execution via specially crafted JWW files.
A buffer overflow vulnerability in CDataMoji of the jwwlib component of LibreCAD 2.2.0-rc3 and older allows an attacker to achieve Remote Code Execution using a crafted JWW documen...

Summary

A buffer overflow vulnerability in CDataMoji of the jwwlib component of LibreCAD 2.2.0-rc3 and older allows an attacker to achieve Remote Code Execution using a crafted JWW document. (CVE-2021-45341)
A buffer overflow vulnerability in CDataList of the jwwlib component of LibreCAD 2.2.0-rc3 and older allows an attacker to achieve Remote Code Execution using a crafted JWW document. (CVE-2021-45342)

References

- https://bugs.mageia.org/show_bug.cgi?id=29996

- https://lists.debian.org/debian-lts-announce/2022/02/msg00002.html

- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/MBLTKH2Q6OBOLSNHIKPW74SFFSC5A2BB/

- https://lists.debian.org/debian-security-announce/2022/msg00044.html

- https://www.cve.org/CVERecord?id=CVE-2021-45341

- https://www.cve.org/CVERecord?id=CVE-2021-45342

Resolution

SRPMS

- 8/core/librecad-2.2.0-0.rc3.1.mga8

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 24 Apr 2022
URL: https://advisories.mageia.org/MGASA-2022-0152.html
Type: security
CVE: CVE-2021-45341, CVE-2021-45342

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here