Debian alert DLA-2908-1 (librecad)
| From: | Markus Koschany <apo@debian.org> | |
| To: | debian-lts-announce <debian-lts-announce@lists.debian.org> | |
| Subject: | [SECURITY] [DLA 2908-1] librecad security update | |
| Date: | Thu, 03 Feb 2022 14:30:16 +0100 | |
| Message-ID: | <d788f18a55995b761dcc06d0543f6957c08f35df.camel@debian.org> |
------------------------------------------------------------------------- Debian LTS Advisory DLA-2908-1 debian-lts@lists.debian.org https://www.debian.org/lts/security/ Markus Koschany February 03, 2022 https://wiki.debian.org/LTS ------------------------------------------------------------------------- Package : librecad Version : 2.1.2-1+deb9u3 CVE ID : CVE-2021-45341 CVE-2021-45342 CVE-2021-45343 Debian Bug : 1004518 Several security vulnerabilities have been discovered in librecad, a computer-aided design (CAD) system. Buffer overflows may lead to remote code execution if a specially crafted JWW document is processed. For Debian 9 stretch, these problems have been fixed in version 2.1.2-1+deb9u3. We recommend that you upgrade your librecad packages. For the detailed security status of librecad please refer to its security tracker page at: https://security-tracker.debian.org/tracker/librecad Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS
