A code execution vulnerability exists in the DL_Dxf::handleLWPolylineData functionality of Ribbonsoft dxflib 3.17.0. A specially-crafted .dxf file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.
The product subtracts one value from another, such that the result is less than the minimum allowable integer value, which produces a value that is not equal to the correct result.
| Name | Vendor | Start Version | End Version | 
|---|---|---|---|
| Dxflib | Ribbonsoft | 3.17.0 (including) | 3.17.0 (including) | 
| Dxflib | Ubuntu | bionic | * | 
| Dxflib | Ubuntu | focal | * | 
| Dxflib | Ubuntu | hirsute | * | 
| Dxflib | Ubuntu | impish | * | 
| Dxflib | Ubuntu | kinetic | * | 
| Dxflib | Ubuntu | lunar | * | 
| Dxflib | Ubuntu | mantic | * | 
| Dxflib | Ubuntu | oracular | * | 
| Dxflib | Ubuntu | trusty | * | 
| Dxflib | Ubuntu | xenial | * |