An issue was discovered in GNU LibreDWG through 0.9.3. Crafted input will lead to a heap-based buffer over-read in decodeR13R2000 in decode.c, a different vulnerability than CVE-2019-20011.
{
"cpe": "cpe:2.3:a:gnu:libredwg:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "0"
},
{
"last_affected": "0.9.3"
}
],
"source": [
"CPE_RANGE",
"REFERENCES"
]
}"2026-07-08T17:17:10Z"
[
{
"signature_type": "Line",
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"213830826583996689317402313247636871493",
"298180385519731208510418832512441301787",
"7303241884940340386907104689857094217",
"320578161566026926538531320737336809925",
"244310063297749902037832346621059482668"
]
},
"signature_version": "v1",
"source": "https://github.com/libredwg/libredwg/commit/f878ba67b638f0d5050b6dba61b9737f64fc53de",
"id": "CVE-2019-20910-f710f2fc",
"target": {
"file": "src/dec_macros.h"
}
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-20910.json"