Advisories ยป MGASA-2022-0152

Updated librecad packages fix security vulnerability

Publication date: 24 Apr 2022
Modification date: 24 Apr 2022
Type: security
Affected Mageia releases : 8
CVE: CVE-2021-45341 , CVE-2021-45342

Description

A buffer overflow vulnerability in CDataMoji of the jwwlib component of
LibreCAD 2.2.0-rc3 and older allows an attacker to achieve Remote Code
Execution using a crafted JWW document. (CVE-2021-45341)

A buffer overflow vulnerability in CDataList of the jwwlib component of
LibreCAD 2.2.0-rc3 and older allows an attacker to achieve Remote Code
Execution using a crafted JWW document. (CVE-2021-45342)
                

References

SRPMS

8/core