An issue was discovered in Open Design Alliance Drawings SDK before 2024.1. A crafted DWG file can force the SDK to reuse an object that has been freed. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code.
References
Link | Resource |
---|---|
https://www.opendesign.com/security-advisories | Vendor Advisory |
https://www.opendesign.com/security-advisories | Vendor Advisory |
Configurations
History
11 Feb 2025, 17:15
Type | Values Removed | Values Added |
---|---|---|
References | () https://www.opendesign.com/security-advisories - Vendor Advisory |
14 Apr 2023, 22:49
Type | Values Removed | Values Added |
---|---|---|
References | (MISC) https://www.opendesign.com/security-advisories - Vendor Advisory | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.8 |
CWE | CWE-416 | |
First Time |
Opendesign drawings Sdk
Opendesign |
|
CPE | cpe:2.3:a:opendesign:drawings_sdk:*:*:*:*:*:*:*:* |
10 Apr 2023, 20:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-04-10 20:15
Updated : 2025-02-11 17:15
NVD link : CVE-2023-26495
Mitre link : CVE-2023-26495
JSON object : View
Products Affected
opendesign
- drawings_sdk
CWE
CWE-416
Use After Free