openSUSE-SU-2023:0201-1

See a problem?
Import Source
https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2023:0201-1.json
JSON Data
https://api.osv.dev/v1/vulns/openSUSE-SU-2023:0201-1
Related
Published
2023-08-02T09:53:16Z
Modified
2023-08-02T09:53:16Z
Summary
Security update for libredwg
Details

This update for libredwg fixes the following issues:

Update to version 0.12.5.5907

Security issues fixed:

  • CVE-2022-33025: Fixed multiple security issues [boo#1200898]
  • CVE-2023-36271: Fixed heap buffer overflow via the function bit_wcs2nlen [boo#1212709]
  • CVE-2023-36272: Fixed heap buffer overflow via the function bitutf8to_TU [boo#1212707]
  • CVE-2023-36273: Fixed heap buffer overflow via the function bitcalcCRC [boo#1212706]
  • CVE-2023-36274: Fixed heap buffer overflow via the function bitwriteTF [boo#1212705]
References

Affected packages

SUSE:Package Hub 15 SP5 / libredwg

Package

Name
libredwg
Purl
pkg:rpm/suse/libredwg&distro=SUSE%20Package%20Hub%2015%20SP5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.12.5.5907-bp155.3.3.1

Ecosystem specific

{
    "binaries": [
        {
            "libredwg-devel": "0.12.5.5907-bp155.3.3.1",
            "libredwg-tools": "0.12.5.5907-bp155.3.3.1",
            "libredwg0": "0.12.5.5907-bp155.3.3.1"
        }
    ]
}

openSUSE:Leap 15.5 / libredwg

Package

Name
libredwg
Purl
pkg:rpm/opensuse/libredwg&distro=openSUSE%20Leap%2015.5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.12.5.5907-bp155.3.3.1

Ecosystem specific

{
    "binaries": [
        {
            "libredwg-devel": "0.12.5.5907-bp155.3.3.1",
            "libredwg-tools": "0.12.5.5907-bp155.3.3.1",
            "libredwg0": "0.12.5.5907-bp155.3.3.1"
        }
    ]
}