cbcvebase.
CVE-2018-16140
published 2018-08-30

CVE-2018-16140: A buffer underwrite vulnerability in get_line() (read.c) in fig2dev 3.2.7a allows an attacker to write prior to the beginning of the buffer via a crafted .fig…

PriorityP335high7.8CVSS 3.0
AVLACLPRNUIRSUCHIHAH
EPSS
1.38%
68.9th percentile
A buffer underwrite vulnerability in get_line() (read.c) in fig2dev 3.2.7a allows an attacker to write prior to the beginning of the buffer via a crafted .fig file.

Affected

8 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
debianfig2dev< fig2dev 1:3.2.7a-3 (bookworm)fig2dev 1:3.2.7a-3 (bookworm)
fig2dev_projectfig2dev
fig2dev_projectfig2dev>= 0 < 1:3.2.7a-31:3.2.7a-3
fig2dev_projectfig2dev>= 0 < 1:3.2.7a-31:3.2.7a-3
fig2dev_projectfig2dev>= 0 < 1:3.2.7a-31:3.2.7a-3
fig2dev_projectfig2dev>= 0 < 1:3.2.7a-31:3.2.7a-3

CVSS provenance

nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv7.8HIGH
vendor_debian7.8LOW
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.