Debian Security Advisory

DLA-3046-1 librecad -- LTS security update

Date Reported:
07 Jun 2022
Affected Packages:
librecad
Vulnerable:
Yes
Security database references:
In Mitre's CVE dictionary: CVE-2021-21897.
More information:

It was discovered that there was a potential heap buffer overflow in librecad, a popular computer-aided design (CAD) system. A specially crafted .dxf file could have led to arbitrary code execution.

  • CVE-2021-21897

    A code execution vulnerability exists in the DL_Dxf::handleLWPolylineData functionality of Ribbonsoft dxflib 3.17.0. A specially-crafted .dxf file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.

For Debian 9 Stretch, these problems have been fixed in version 2.1.2-1+deb9u4.

We recommend that you upgrade your librecad packages.

Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS