{ "id": "CVE-2023-22669", "sourceIdentifier": "cve@mitre.org", "published": "2023-04-15T01:15:06.970", "lastModified": "2023-04-15T02:25:57.407", "vulnStatus": "Awaiting Analysis", "descriptions": [ { "lang": "en", "value": "Parsing of DWG files in Open Design Alliance Drawings SDK before 2023.6 lacks proper validation of the length of user-supplied XRecord data prior to copying it to a fixed-length heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process." } ], "metrics": {}, "references": [ { "url": "https://www.opendesign.com/security-advisories", "source": "cve@mitre.org" } ] }