Impact
A heap‑based buffer overflow occurs during the execution of the bit_read_RC function in the Dwgbmp Utility of GNU libredwg. The vulnerability allows an attacker to overflow a heap buffer, potentially leading to arbitrary code execution or privilege escalation on the affected system. The flaw is detectable through malformed DWG files processed by the utility, and the exploit has already been published for remote exploitation.
Affected Systems
GNU libredwg versions up to 0.13.4.8160 are affected. Any system that uses this library and processes DWG files is at risk. The vulnerability is present in the bits.c component of the Dwgbmp Utility module.
Risk and Exploitability
The CVSS score of 6.9 indicates a medium severity risk. No EPSS score is available, but an exploit has been published and could be deployed remotely. The flaw is not listed in CISA’s KEV catalog, yet the existence of a public exploit and remote attack capability make it a priority for patching.
OpenCVE Enrichment