Heap buffer overflow vulnerability in LibreDWG versions v0.13.3.7571 up to v0.13.3.7835 allows a crafted DWG file to cause a Denial of Service (DoS) via the function decompress_R2004_section at decode.c.
References
| Link | Resource |
|---|---|
| https://davizin.com/cves/CVE-2025-61154.html | Third Party Advisory |
| https://github.com/LibreDWG/libredwg/issues/1180 | Issue Tracking |
Configurations
History
02 Jun 2026, 18:43
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://davizin.com/cves/CVE-2025-61154.html - Third Party Advisory | |
| References | () https://github.com/LibreDWG/libredwg/issues/1180 - Issue Tracking | |
| CPE | cpe:2.3:a:gnu:libredwg:*:*:*:*:*:*:*:* | |
| First Time |
Gnu libredwg
Gnu |
16 Mar 2026, 14:18
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-122 | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.5 |
| Summary |
|
12 Mar 2026, 19:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-03-12 19:16
Updated : 2026-06-02 18:43
NVD link : CVE-2025-61154
Mitre link : CVE-2025-61154
CVE.ORG link : CVE-2025-61154
JSON object : View
Products Affected
gnu
- libredwg
CWE
CWE-122
Heap-based Buffer Overflow
