CVE-2020-23861: GNU Libredwg
Medium severity, CVSS 5.5. EPSS: 0.6% chance of exploitation in the next 30 days.
A heap-based buffer overflow vulnerability exists in LibreDWG 0.10.1 via the read_system_page function at libredwg-0.10.1/src/decode_r2007.c:666:5, which causes a denial of service by submitting a dwg file.
Affected products
- GNU Libredwg: version 0.10.1 only
Published 2021-05-18. Last modified 2026-06-17.