FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

librecad -- out-of-bounds read in importshp plugin

Affected packages
librecad < 2.2.0.1

Details

VuXML ID b67d768c-1f53-11ee-82ed-4ccc6adda413
Discovery 2021-12-28
Entry 2023-07-10

Albin Eldstål-Ahrens reports:

An out-of-bounds read on a heap buffer in the importshp plugin may allow an attacker to read sensitive data via a crafted DBF file.

References

CVE Name CVE-2023-30259
URL https://github.com/LibreCAD/LibreCAD/issues/1481