Xfig fig2dev 3.2.7a has a stack-based buffer overflow in the calc_arrow function in bound.c.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade fig2dev | Jan 23, 2020 | Jul 26, 2019 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jul 26, 2019 |
| Suse | — | Upgrade transfig | Jul 1, 2020 | Jul 26, 2019 |
| Ubuntu | — | Upgrade transfigUpgrade fig2dev | Mar 22, 2023 | Jul 26, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub