A buffer overflow vulnerability in CDataMoji of the jwwlib component of LibreCAD 2.2.0-rc3 and older allows an attacker to achieve Remote Code Execution using a crafted JWW document.
| Software | From | Fixed in |
|---|---|---|
| librecad / librecad | 2.2.0-rc3 | 2.2.0-rc3.x |
| librecad / librecad | 2.2.0-rc1 | 2.2.0-rc1.x |
| librecad / librecad | 2.2.0-rc2 | 2.2.0-rc2.x |
| librecad / librecad | - | 2.2.0 |
| fedoraproject / fedora | 34 | 34.x |
| fedoraproject / fedora | 35 | 35.x |
| debian / debian_linux | 10.0 | 10.0.x |
| debian / debian_linux | 11.0 | 11.0.x |