Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:33329
HistoryDec 14, 2021 - 8:13 p.m.

Remote Code Execution (RCE)

2021-12-1420:13:04
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
17
remote code execution
librecad
heap buffer overflow
dwgcompressor
malicious script
software vulnerability

EPSS

0.009

Percentile

83.0%

librecad is vulnerable to remote code execution. The vulnerability exists due to a heap buffer overflow in the dwgCompressor::copyCompBytes21 functionality of LibreCad libdxfrw allowing a specially-crafted .dwg file execute maliciously crafted script.