cbcvebase.
CVE-2017-16899
published 2017-11-20

CVE-2017-16899: An array index error in the fig2dev program in Xfig 3.2.6a allows remote attackers to cause a denial-of-service attack or information disclosure with a…

high7.1CVSS 3.0
AVLACLPRNUIRSUCHINAH
An array index error in the fig2dev program in Xfig 3.2.6a allows remote attackers to cause a denial-of-service attack or information disclosure with a maliciously crafted Fig format file, related to a negative font value in dev/gentikz.c, and the read_textobject functions in read.c and read1_3.c.

Affected

8 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debiandebian_linux
debianfig2dev< fig2dev 1:3.2.6a-5 (bookworm)fig2dev 1:3.2.6a-5 (bookworm)
fig2dev_projectfig2dev>= 0 < 1:3.2.6a-51:3.2.6a-5
fig2dev_projectfig2dev>= 0 < 1:3.2.6a-51:3.2.6a-5
fig2dev_projectfig2dev>= 0 < 1:3.2.6a-51:3.2.6a-5
fig2dev_projectfig2dev>= 0 < 1:3.2.6a-51:3.2.6a-5
xfig_projectxfig

CVSS provenance

nvdv3.07.1HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
osv7.1HIGH