LibreDWG v0.12.5 was discovered to contain a heap buffer overflow via the function bitutf8to_TU at bits.c.