Alerts This Week
Warning Icon 1 619
Alerts This Week
Warning Icon 1 619

openSUSE: 2022:0067-1 Important Threat Fix For LibDXFRW And LibreCAD

opensuse
Calendar Grey March 2, 2022
Dist Opensuse Esm H88
This revision targets essential LibDXFRW and LibreCAD vulnerabilities, tackling various heap, buffer, and write risks.
An update that fixes three vulnerabilities is now available

Description

This update for libdxfrw, librecad fixes the following issues:

- Update to version 1.0.1+git.20220109:

* fixed ambiguous error for DRW_Dimension::parseDwg()

* fixed enless while()-loop for pre 2004 versions

* dwgReader::readDwgObjects() stop reading after 1st error

* dwgReader::readDwgEntities() stop reading after 1st error

* replace ENTRY_PARSE macro with template method

* remove unused DRW_Class::parseCode() method

* protect vector<>.reserve() calls

* Added NULL check for hatch code 93

* Fix bounds check in DRW_LWPolyline

* fix, check maxClassNum for valid value

* fixed wrong 2010+ check for 64-bit size

* Set compiler warnings on by default, because makes harder for bugs to

go undetected. modified: CMakeLists.txt

* Fixed fall through and other warnings (#54)

* fix "Vertex ID" printout

- Update to version 1.0.1+git.20211110:

* fixed heap use after free vulnerability CVE-2021-21900...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Backports SLE-15-SP3:

zypper in -t patch openSUSE-2022-67=1

Package List

- openSUSE Backports SLE-15-SP3 (aarch64 i586 ppc64le s390x x86_64):

libdxfrw-devel-1.0.1+git.20220109-bp153.2.3.1

libdxfrw-tools-1.0.1+git.20220109-bp153.2.3.1

libdxfrw1-1.0.1+git.20220109-bp153.2.3.1

- openSUSE Backports SLE-15-SP3 (aarch64 ppc64le s390x x86_64):

librecad-2.2.0~rc3-bp153.2.3.1

librecad-debuginfo-2.2.0~rc3-bp153.2.3.1

librecad-debugsource-2.2.0~rc3-bp153.2.3.1

- openSUSE Backports SLE-15-SP3 (noarch):

librecad-parts-2.2.0~rc3-bp153.2.3.1

References

https://www.suse.com/security/cve/CVE-2021-21898.html

https://www.suse.com/security/cve/CVE-2021-21899.html

https://www.suse.com/security/cve/CVE-2021-21900.html

https://bugzilla.suse.com/1192936

https://bugzilla.suse.com/1192937

https://bugzilla.suse.com/1192938

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2022:0067-1
Rating: important
Affected Products: openSUSE Backports SLE-15-SP3 .

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here