rpm package
opensuse/transfig&distro=openSUSE Tumbleweed
pkg:rpm/opensuse/transfig&distro=openSUSE%20Tumbleweed
Vulnerabilities (26)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2019-19797 | — | < 3.2.8a-5.1 | 3.2.8a-5.1 | Dec 15, 2019 | read_colordef in read.c in Xfig fig2dev 3.2.7b has an out-of-bounds write. | ||
| CVE-2019-19746 | — | < 3.2.8a-5.1 | 3.2.8a-5.1 | Dec 12, 2019 | make_arrow in arrow.c in Xfig fig2dev 3.2.7b allows a segmentation fault and out-of-bounds write because of an integer overflow via a large arrow type. | ||
| CVE-2019-19555 | — | < 3.2.8a-5.1 | 3.2.8a-5.1 | Dec 4, 2019 | read_textobject in read.c in Xfig fig2dev 3.2.7b has a stack-based buffer overflow because of an incorrect sscanf. | ||
| CVE-2019-14275 | — | < 3.2.8a-5.1 | 3.2.8a-5.1 | Jul 26, 2019 | Xfig fig2dev 3.2.7a has a stack-based buffer overflow in the calc_arrow function in bound.c. | ||
| CVE-2018-16140 | — | < 3.2.8a-5.1 | 3.2.8a-5.1 | Aug 30, 2018 | A buffer underwrite vulnerability in get_line() (read.c) in fig2dev 3.2.7a allows an attacker to write prior to the beginning of the buffer via a crafted .fig file. | ||
| CVE-2017-16899 | Hig | 7.1 | < 3.2.8a-5.1 | 3.2.8a-5.1 | Nov 20, 2017 | An array index error in the fig2dev program in Xfig 3.2.6a allows remote attackers to cause a denial-of-service attack or information disclosure with a maliciously crafted Fig format file, related to a negative font value in dev/gentikz.c, and the read_textobject functions in rea |
- CVE-2019-19797Dec 15, 2019affected < 3.2.8a-5.1fixed 3.2.8a-5.1
read_colordef in read.c in Xfig fig2dev 3.2.7b has an out-of-bounds write.
- CVE-2019-19746Dec 12, 2019affected < 3.2.8a-5.1fixed 3.2.8a-5.1
make_arrow in arrow.c in Xfig fig2dev 3.2.7b allows a segmentation fault and out-of-bounds write because of an integer overflow via a large arrow type.
- CVE-2019-19555Dec 4, 2019affected < 3.2.8a-5.1fixed 3.2.8a-5.1
read_textobject in read.c in Xfig fig2dev 3.2.7b has a stack-based buffer overflow because of an incorrect sscanf.
- CVE-2019-14275Jul 26, 2019affected < 3.2.8a-5.1fixed 3.2.8a-5.1
Xfig fig2dev 3.2.7a has a stack-based buffer overflow in the calc_arrow function in bound.c.
- CVE-2018-16140Aug 30, 2018affected < 3.2.8a-5.1fixed 3.2.8a-5.1
A buffer underwrite vulnerability in get_line() (read.c) in fig2dev 3.2.7a allows an attacker to write prior to the beginning of the buffer via a crafted .fig file.
- affected < 3.2.8a-5.1fixed 3.2.8a-5.1
An array index error in the fig2dev program in Xfig 3.2.6a allows remote attackers to cause a denial-of-service attack or information disclosure with a maliciously crafted Fig format file, related to a negative font value in dev/gentikz.c, and the read_textobject functions in rea
Page 2 of 2