Description
Parsing of DWG files in Open Design Alliance Drawings SDK before 2023.6 lacks proper validation of the length of user-supplied XRecord data prior to copying it to a fixed-length heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-26798 | Parsing of DWG files in Open Design Alliance Drawings SDK before 2023.6 lacks proper validation of the length of user-supplied XRecord data prior to copying it to a fixed-length heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. |
References
| Link | Providers |
|---|---|
| https://www.opendesign.com/security-advisories |
|
History
Mon, 05 May 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-05-05T16:05:58.997Z
Reserved: 2023-01-06T00:00:00.000Z
Link: CVE-2023-22669
Updated: 2024-08-02T10:13:50.096Z
Status : Modified
Published: 2023-04-15T01:15:06.970
Modified: 2025-05-05T16:15:29.547
Link: CVE-2023-22669
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD