CVE-2018-16140
published 2018-08-30CVE-2018-16140: A buffer underwrite vulnerability in get_line() (read.c) in fig2dev 3.2.7a allows an attacker to write prior to the beginning of the buffer via a crafted .fig…
PriorityP335high7.8CVSS 3.0
AVLACLPRNUIRSUCHIHAH
EPSS
1.38%
68.9th percentile
A buffer underwrite vulnerability in get_line() (read.c) in fig2dev 3.2.7a allows an attacker to write prior to the beginning of the buffer via a crafted .fig file.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | fig2dev | < fig2dev 1:3.2.7a-3 (bookworm) | fig2dev 1:3.2.7a-3 (bookworm) |
| fig2dev_project | fig2dev | — | — |
| fig2dev_project | fig2dev | >= 0 < 1:3.2.7a-3 | 1:3.2.7a-3 |
| fig2dev_project | fig2dev | >= 0 < 1:3.2.7a-3 | 1:3.2.7a-3 |
| fig2dev_project | fig2dev | >= 0 < 1:3.2.7a-3 | 1:3.2.7a-3 |
| fig2dev_project | fig2dev | >= 0 < 1:3.2.7a-3 | 1:3.2.7a-3 |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv7.8HIGH
vendor_debian7.8LOW
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-8j2g-wgpq-4f6c: A buffer underwrite vulnerability in get_line() (read
ghsa_unreviewed·2022-05-13
CVE-2018-16140 [HIGH] CWE-787 GHSA-8j2g-wgpq-4f6c: A buffer underwrite vulnerability in get_line() (read
A buffer underwrite vulnerability in get_line() (read.c) in fig2dev 3.2.7a allows an attacker to write prior to the beginning of the buffer via a crafted .fig file.
OSV
CVE-2018-16140: A buffer underwrite vulnerability in get_line() (read
osv·2018-08-30·CVSS 7.8
CVE-2018-16140 [HIGH] CVE-2018-16140: A buffer underwrite vulnerability in get_line() (read
A buffer underwrite vulnerability in get_line() (read.c) in fig2dev 3.2.7a allows an attacker to write prior to the beginning of the buffer via a crafted .fig file.
Red Hat
transfig: Buffer underwrite in read.c:get_line() via crafted FIG file
vendor_redhat·2018-09-12·CVSS 7.8
CVE-2018-16140 [HIGH] CWE-119 transfig: Buffer underwrite in read.c:get_line() via crafted FIG file
transfig: Buffer underwrite in read.c:get_line() via crafted FIG file
A buffer underwrite vulnerability in get_line() (read.c) in fig2dev 3.2.7a allows an attacker to write prior to the beginning of the buffer via a crafted .fig file.
The fig2dev utility, as shipped with the transfig package, is vulnerable to one-byte buffer underwrite in get_line() function when processing specially crafted FIG file, having only minimal security impact in most situations.
Statement: This issue affects the versions of transfig as shipped with Red Hat Enterprise Linux 5. Red Hat Enterprise Linux 5 is now in Extended Life Phase of the support and maintenance life cycle. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Red Hat Enterprise Linux
Ubuntu
transfig vulnerability
vendor_ubuntu·2018-09-06
CVE-2018-16140 transfig vulnerability
Title: transfig vulnerability
Summary: transfig could be made to execute arbitrary code if it received a
specially crafted FIG file.
It was discovered that transfig incorrectly handled certain FIG files.
An attacker could possibly use this to execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2018-16140: fig2dev - A buffer underwrite vulnerability in get_line() (read.c) in fig2dev 3.2.7a allow...
vendor_debian·2018·CVSS 7.8
CVE-2018-16140 [HIGH] CVE-2018-16140: fig2dev - A buffer underwrite vulnerability in get_line() (read.c) in fig2dev 3.2.7a allow...
A buffer underwrite vulnerability in get_line() (read.c) in fig2dev 3.2.7a allows an attacker to write prior to the beginning of the buffer via a crafted .fig file.
Scope: local
bookworm: resolved (fixed in 1:3.2.7a-3)
bullseye: resolved (fixed in 1:3.2.7a-3)
forky: resolved (fixed in 1:3.2.7a-3)
sid: resolved (fixed in 1:3.2.7a-3)
trixie: resolved (fixed in 1:3.2.7a-3)
No detection rules found.
Bugzilla
CVE-2018-16140 transfig: Buffer underwrite in read.c:get_line() via crafted FIG file [fedora-all]
bugzilla·2018-09-25·CVSS 7.8
CVE-2018-16140 [HIGH] CVE-2018-16140 transfig: Buffer underwrite in read.c:get_line() via crafted FIG file [fedora-all]
CVE-2018-16140 transfig: Buffer underwrite in read.c:get_line() via crafted FIG file [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multipl
Bugzilla
CVE-2018-16140 transfig: Buffer underwrite in read.c:get_line() via crafted FIG file
bugzilla·2018-09-12·CVSS 7.8
CVE-2018-16140 [HIGH] CVE-2018-16140 transfig: Buffer underwrite in read.c:get_line() via crafted FIG file
CVE-2018-16140 transfig: Buffer underwrite in read.c:get_line() via crafted FIG file
A buffer underwrite vulnerability in get_line() (read.c) in fig2dev 3.2.7a allows an attacker to write prior to the beginning of the buffer via a crafted .fig file.
Upstream Bug:
https://sourceforge.net/p/mcj/tickets/28/
Upstream Patch:
https://sourceforge.net/p/mcj/fig2dev/ci/e0c4b02429116b15ad1568c2c425f06b95b95830
Discussion:
Created transfig tracking bugs for this issue:
Affects: fedora-all [bug 1627975]
---
Reproduces on F28 with transfig-3.2.6a-2.fc28.x86_64:
# fig2dev -L tikz CVE-2018-16140 2>&1 | ./asan_symbolizer.py
Invalid color definition: , setting to black (#00000).
Invalid color definition: 0, setting to black (#00000).
Invalid color definition: 0, setting to black (#00000).
Cann
Bugzilla
CVE-2018-16140 transfig: Buffer underwrite in read.c:get_line() via crafted FIG file [fedora-all]
bugzilla·2018-09-12·CVSS 7.8
CVE-2018-16140 [HIGH] CVE-2018-16140 transfig: Buffer underwrite in read.c:get_line() via crafted FIG file [fedora-all]
CVE-2018-16140 transfig: Buffer underwrite in read.c:get_line() via crafted FIG file [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multipl
2018-08-30
Published