A buffer underwrite vulnerability in get_line() (read.c) in fig2dev 3.2.7a allows an attacker to write prior to the beginning of the buffer via a crafted .fig file.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade fig2dev | Jan 23, 2020 | Aug 30, 2018 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Aug 30, 2018 |
| Suse | — | Upgrade transfig | May 28, 2019 | Aug 29, 2018 |
| Ubuntu | — | Upgrade transfig | Sep 19, 2018 | Aug 29, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub