Application crash via unchecked DWG page count
Published Jan 2, 2024 · Updated Nov 14, 2024
Out-of-bounds read in LibreDWG before 0.12.5.6384 allows local users to crash applications by supplying a crafted R2007 DWG file. The read_sections_map function accepts an excessive section->num_pages value without resetting it, and read_data_section then indexes beyond the section->pages array. The target must process the file through LibreDWG; the demonstrated result is a segmentation fault in the consuming process.
Summary
What happened
Out-of-bounds read in LibreDWG before 0.12.5.6384 allows local users to crash applications by supplying a crafted R2007 DWG file. The read_sections_map function accepts an excessive section->num_pages value without resetting it, and read_data_section then indexes beyond the section->pages array. The target must process the file through LibreDWG; the demonstrated result is a segmentation fault in the consuming process.
The record
- CVE
- CVE-2023-26157
- Published
- Jan 2, 2024
- Updated
- Nov 14, 2024
- Vendor
- The GnuPG Project
- Product
- LibreDWG
- Classifications
- CWE-400, CWE-125, T1499.004
- Attack vector
- local
- Privileges
- authenticated
Timeline
How it unfolded
- Jan 2, 2024CVE publishedPublication date reported by the CVE source.
- Nov 14, 2024Record updatedLatest update available in the CVE record.
Exploitability
Present is not the same as exploitable
Compare your product and version with the public record. A matching version still requires validation against your environment.
Is a vulnerable build present?
Compare these published version ranges with your installed build and any vendor patches.
- Affected versionversion=0 <0.12.5.6384
What conditions does exploitation require?
What is affected?
Attacks
What attackers are doing with it
Daily unique IPs observed by Shadowserver honeypots for known exploited vulnerabilities (KEVs). Missing observations do not establish an absence of attacks.
Weakness, pattern, technique
Public exploit references
- Issue 850 crafted DWG crash reproducerproof of concept · demonstrated
Labels summarize the accepted research assessment. They do not indicate a test against your environment.
Technologies
Your stack
See the directory against your own environment.
Your stack
Check the software in your environment
Book a demo to see how Hinoki identifies affected software and validates exploitability in your environment.
Book a demo