{"id":"openSUSE-SU-2020:0096-1","summary":"Security update for libredwg","details":"This update for libredwg fixes the following issues:\n\nlibredwg was updated to release 0.10:\n\nAPI breaking changes:\n\n* Added a new int *isnewp argument to all dynapi utf8text\n  getters, if the returned string is freshly malloced or not.\n* removed the UNKNOWN supertype, there are only UNKNOWN_OBJ and\n  UNKNOWN_ENT left, with common_entity_data.\n* renamed BLOCK_HEADER.preview_data to preview,\n  preview_data_size to preview_size.\n* renamed SHAPE.shape_no to style_id.\n* renamed CLASS.wasazombie to is_zombie.\n\nBugfixes:\n\n* Harmonized INDXFB with INDXF, removed extra src/in_dxfb.c.\n* Fixed encoding of added r2000 AUXHEADER address.\n* Fixed EED encoding from dwgrewrite.\n* Add several checks against\n    [CVE-2020-6609, boo#1160520], [CVE-2020-6610, boo#1160522],\n    [CVE-2020-6611, boo#1160523], [CVE-2020-6612, boo#1160524],\n    [CVE-2020-6613, boo#1160525], [CVE-2020-6614, boo#1160526],\n    [CVE-2020-6615, boo#1160527]","modified":"2026-02-04T02:45:22.919312Z","published":"2020-01-22T23:11:47Z","related":["CVE-2020-6609","CVE-2020-6610","CVE-2020-6611","CVE-2020-6612","CVE-2020-6613","CVE-2020-6614","CVE-2020-6615"],"upstream":["CVE-2020-6609","CVE-2020-6610","CVE-2020-6611","CVE-2020-6612","CVE-2020-6613","CVE-2020-6614","CVE-2020-6615"],"references":[{"type":"ADVISORY","url":"https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/SECBSD34W2KNYYJEF4TYMEZJKZ4FZ4PV/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1160520"},{"type":"REPORT","url":"https://bugzilla.suse.com/1160522"},{"type":"REPORT","url":"https://bugzilla.suse.com/1160523"},{"type":"REPORT","url":"https://bugzilla.suse.com/1160524"},{"type":"REPORT","url":"https://bugzilla.suse.com/1160525"},{"type":"REPORT","url":"https://bugzilla.suse.com/1160526"},{"type":"REPORT","url":"https://bugzilla.suse.com/1160527"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-6609"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-6610"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-6611"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-6612"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-6613"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-6614"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-6615"}],"affected":[{"package":{"name":"libredwg","ecosystem":"openSUSE:Leap 15.1","purl":"pkg:rpm/opensuse/libredwg&distro=openSUSE%20Leap%2015.1"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.10-lp151.2.6.1"}]}],"ecosystem_specific":{"binaries":[{"libredwg-devel":"0.10-lp151.2.6.1","libredwg-tools":"0.10-lp151.2.6.1","libredwg0":"0.10-lp151.2.6.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2020:0096-1.json"}}],"schema_version":"1.7.3"}