Impact
The vulnerability is a heap-based buffer overflow in the decompress_R2004_section routine of LibreDWG 0.13.4-154-g0b573035. It is triggered when decoding a specially crafted R2004 section in a DWG file. The overflow can corrupt heap memory, potentially causing the program to crash or, if the attacker controls the overwritten data, could lead to arbitrary code execution within the process.
Affected Systems
The flaw exists in GNU LibreDWG versions up to and including 0.13.4-154-g0b573035. The official fix is implemented in release 0.14.8396, which corresponds to commit 3d0f9fc2eddbd6579c99af3111c37c98f03475d0. Any system running LibreDWG before this version is vulnerable when it processes DWG files that can be supplied locally.
Risk and Exploitability
Exploitation requires local access to the machine where LibreDWG is executing, restricting the threat to local users. The CVSS score of 4.8 indicates moderate severity, and the EPSS score of <1% reflects a very low but non-zero likelihood of exploitation. The flaw is not listed in the CISA KEV catalog. Because only local attackers can trigger the overflow and the vulnerability has a publicly available patch, the overall risk to remote attackers is limited but organizations should still address the issue promptly.
OpenCVE Enrichment