cbcvebase.
CVE-2018-16140
published 2018-08-30

CVE-2018-16140: A buffer underwrite vulnerability in get_line() (read.c) in fig2dev 3.2.7a allows an attacker to write prior to the beginning of the buffer via a crafted .fig…

high7.8CVSS 3.0
AVLACLPRNUIRSUCHIHAH
A buffer underwrite vulnerability in get_line() (read.c) in fig2dev 3.2.7a allows an attacker to write prior to the beginning of the buffer via a crafted .fig file.

Affected

8 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
debianfig2dev< fig2dev 1:3.2.7a-3 (bookworm)fig2dev 1:3.2.7a-3 (bookworm)
fig2dev_projectfig2dev
fig2dev_projectfig2dev>= 0 < 1:3.2.7a-31:3.2.7a-3
fig2dev_projectfig2dev>= 0 < 1:3.2.7a-31:3.2.7a-3
fig2dev_projectfig2dev>= 0 < 1:3.2.7a-31:3.2.7a-3
fig2dev_projectfig2dev>= 0 < 1:3.2.7a-31:3.2.7a-3

CVSS provenance

nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv7.8HIGH