An issue was discovered in fig2dev before 3.2.8.. A NULL pointer dereference exists in the function compute_closed_spline() located in trans_spline.c. It allows an attacker to cause Denial of Service. The fixed version of fig2dev is 3.2.8.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade transfigUpgrade transfig-debuginfo | Aug 8, 2023 | Sep 20, 2021 |
| Amazon_linux | — | Upgrade transfig | Aug 23, 2023 | Sep 20, 2021 |
| Debian | — | Upgrade fig2dev | Nov 29, 2021 | Sep 20, 2021 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Sep 20, 2021 |
| Suse | — | Upgrade transfig | Oct 30, 2021 | Sep 20, 2021 |
| Ubuntu | — | Upgrade fig2devUpgrade transfig | Mar 22, 2023 | Sep 20, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub