cbcvebase.
CVE-2009-1962
published 2009-06-08

CVE-2009-1962: Xfig, possibly 3.2.5, allows local users to read and write arbitrary files via a symlink attack on the (1) xfig-eps[PID], (2) xfig-pic[PID].pix, (3)…

PriorityP417medium4.4CVSS 2.0
AVLACMAuNCPIPAP
EPSS
0.33%
25.8th percentile
Xfig, possibly 3.2.5, allows local users to read and write arbitrary files via a symlink attack on the (1) xfig-eps[PID], (2) xfig-pic[PID].pix, (3) xfig-pic[PID].err, (4) xfig-pcx[PID].pix, (5) xfig-xfigrc[PID], (6) xfig[PID], (7) xfig-print[PID], (8) xfig-export[PID].err, (9) xfig-batch[PID], (10) xfig-exp[PID], or (11) xfig-spell.[PID] temporary files, where [PID] is a process ID.

Affected

8 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debiandebian_linux
debianxfig< xfig 1:3.2.5.a-1 (bookworm)xfig 1:3.2.5.a-1 (bookworm)
xfigxfig
xfigxfig>= 0 < 1:3.2.5.a-11:3.2.5.a-1
xfigxfig>= 0 < 1:3.2.5.a-11:3.2.5.a-1
xfigxfig>= 0 < 1:3.2.5.a-11:3.2.5.a-1
xfigxfig>= 0 < 1:3.2.5.a-11:3.2.5.a-1

CVSS provenance

nvdv2.04.4MEDIUMAV:L/AC:M/Au:N/C:P/I:P/A:P
osv4.4MEDIUM
vendor_debian4.4MEDIUM
vendor_redhat4.4MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.