make_arrow in arrow.c in Xfig fig2dev 3.2.7b allows a segmentation fault and out-of-bounds write because of an integer overflow via a large arrow type.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade transfigUpgrade transfig-debuginfo | Apr 27, 2020 | Dec 12, 2019 |
| Debian | — | Upgrade fig2dev | Jul 30, 2024 | Dec 12, 2019 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Dec 12, 2019 |
| Suse | — | Upgrade transfig | Jul 23, 2021 | Dec 12, 2019 |
| Ubuntu | — | No solution exists | Jun 26, 2025 | Dec 12, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub