Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:33332
HistoryDec 14, 2021 - 8:42 p.m.

Remote Code Execution (RCE)

2021-12-1420:42:36
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
15
code execution
vulnerability
librecad
dxfrw
use-after-free
attack
malicious file

EPSS

0.009

Percentile

83.2%

A code execution vulnerability exists in the dxfRW::processLType() functionality of LibreCad libdxfrw 2.2.0-rc2-19-ge02f3580. A specially-crafted .dxf file can lead to a use-after-free vulnerability. An attacker can provide a malicious file to trigger this vulnerability.