Debian Security Advisory
DLA-3046-1 librecad -- LTS security update
- Date Reported:
- 07 Jun 2022
- Affected Packages:
- Security database references:
- In Mitre's CVE dictionary: CVE-2021-21897.
- More information:
It was discovered that there was a potential heap buffer overflow in librecad, a popular computer-aided design (CAD) system. A specially crafted .dxf file could have led to arbitrary code execution.
A code execution vulnerability exists in the DL_Dxf::handleLWPolylineData functionality of Ribbonsoft dxflib 3.17.0. A specially-crafted .dxf file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.
For Debian 9
Stretch, these problems have been fixed in version 2.1.2-1+deb9u4.
We recommend that you upgrade your librecad packages.
Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS