Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:35992
HistoryJun 15, 2022 - 2:30 a.m.

Remote Code Execution (RCE)

2022-06-1502:30:48
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
13
librecad
remote code execution
dxf file
heap buffer overflow
vulnerability

EPSS

0.011

Percentile

85.0%

librecad is vulnerable to remote code execution. The vulnerability exists due to a heap buffer overflow in DL_Dxf::handleLWPolylineData functionality of Ribbonsoft dxflib allowing an attacker to inject maliciously crafted script into the system via a specially-crafted .dxf file.