A code execution vulnerability exists in the DL_Dxf::handleLWPolylineData functionality of Ribbonsoft dxflib 3.17.0. A specially-crafted .dxf file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.
The product subtracts one value from another, such that the result is less than the minimum allowable integer value, which produces a value that is not equal to the correct result.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Dxflib | Ribbonsoft | 3.17.0 (including) | 3.17.0 (including) |
Dxflib | Ubuntu | bionic | * |
Dxflib | Ubuntu | hirsute | * |
Dxflib | Ubuntu | impish | * |
Dxflib | Ubuntu | kinetic | * |
Dxflib | Ubuntu | lunar | * |
Dxflib | Ubuntu | mantic | * |
Dxflib | Ubuntu | trusty | * |
Dxflib | Ubuntu | xenial | * |