CVE-2021-3561
published 2021-05-26CVE-2021-3561: An Out of Bounds flaw was found fig2dev version 3.2.8a. A flawed bounds check in read_objects() could allow an attacker to provide a crafted malicious input…
PriorityP428high7.1CVSS 3.1
AVLACLPRNUIRSUCNIHAH
EPSS
1.18%
64.0th percentile
An Out of Bounds flaw was found fig2dev version 3.2.8a. A flawed bounds check in read_objects() could allow an attacker to provide a crafted malicious input causing the application to either crash or in some cases cause memory corruption. The highest threat from this vulnerability is to integrity as well as system availability.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | fig2dev | < fig2dev 1:3.2.8-3 (bookworm) | fig2dev 1:3.2.8-3 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fig2dev_project | fig2dev | — | — |
| fig2dev_project | fig2dev | — | — |
| fig2dev_project | fig2dev | >= 0 < 1:3.2.8-3 | 1:3.2.8-3 |
| fig2dev_project | fig2dev | >= 0 < 1:3.2.8-3 | 1:3.2.8-3 |
| fig2dev_project | fig2dev | >= 0 < 1:3.2.8-3 | 1:3.2.8-3 |
| fig2dev_project | fig2dev | >= 0 < 1:3.2.8-3 | 1:3.2.8-3 |
| fig2dev_project | fig2dev | >= 0 < 1:3.2.6a-6ubuntu1.1 | 1:3.2.6a-6ubuntu1.1 |
| fig2dev_project | fig2dev | >= 0 < 1:3.2.7a-7ubuntu0.1 | 1:3.2.7a-7ubuntu0.1 |
CVSS provenance
nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:P
osv7.1HIGH
vendor_debian7.1HIGH
vendor_redhat7.1HIGH
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
fig2dev vulnerabilities
osv·2023-02-13·CVSS 5.5
CVE-2019-14275 [MEDIUM] fig2dev vulnerabilities
fig2dev vulnerabilities
Frederic Cambus discovered that Fig2dev incorrectly handled certain image
files. If a user or an automated system were tricked into opening a certain
specially crafted input file, a remote attacker could possibly use this issue
to cause a denial of service. This issue only affected Ubuntu 18.04 LTS.
(CVE-2019-14275)
It was discovered that Fig2dev incorrectly handled certain image files. If
a user or an automated system were tricked into opening a certain specially
crafted input file, a remote attacker could possibly use this issue to cause
a denial of service. (CVE-2019-19555, CVE-2019-19797, CVE-2020-21529,
CVE-2020-21530, CVE-2020-21531, CVE-2020-21532, CVE-2020-21533,
CVE-2020-21534, CVE-2020-21535, CVE-2020-21675, CVE-2020-21676,
CVE-2021-3561)
It was discove
GHSA
GHSA-w359-m9m3-v2w3: An Out of Bounds flaw was found fig2dev version 3
ghsa_unreviewed·2022-05-24
CVE-2021-3561 [HIGH] CWE-119 GHSA-w359-m9m3-v2w3: An Out of Bounds flaw was found fig2dev version 3
An Out of Bounds flaw was found fig2dev version 3.2.8a. A flawed bounds check in read_objects() could allow an attacker to provide a crafted malicious input causing the application to either crash or in some cases cause memory corruption. The highest threat from this vulnerability is to integrity as well as system availability.
OSV
CVE-2021-3561: An Out of Bounds flaw was found fig2dev version 3
osv·2021-05-26·CVSS 7.1
CVE-2021-3561 [HIGH] CVE-2021-3561: An Out of Bounds flaw was found fig2dev version 3
An Out of Bounds flaw was found fig2dev version 3.2.8a. A flawed bounds check in read_objects() could allow an attacker to provide a crafted malicious input causing the application to either crash or in some cases cause memory corruption. The highest threat from this vulnerability is to integrity as well as system availability.
Ubuntu
Fig2dev vulnerabilities
vendor_ubuntu·2023-02-13·CVSS 5.5
CVE-2019-19797 [MEDIUM] Fig2dev vulnerabilities
Title: Fig2dev vulnerabilities
Summary: Several security issues were fixed in Fig2dev.
Frederic Cambus discovered that Fig2dev incorrectly handled certain image
files. If a user or an automated system were tricked into opening a certain
specially crafted input file, a remote attacker could possibly use this issue
to cause a denial of service. This issue only affected Ubuntu 18.04 LTS.
(CVE-2019-14275)
It was discovered that Fig2dev incorrectly handled certain image files. If
a user or an automated system were tricked into opening a certain specially
crafted input file, a remote attacker could possibly use this issue to cause
a denial of service. (CVE-2019-19555, CVE-2019-19797, CVE-2020-21529,
CVE-2020-21530, CVE-2020-21531, CVE-2020-21532, CVE-2020-21533,
CVE-2020-21534, CVE-2020-21535
Red Hat
fig2dev: Global buffer overflow in fig2dev/read.c in function read_objects
vendor_redhat·2021-04-26·CVSS 7.1
CVE-2021-3561 [HIGH] CWE-119 fig2dev: Global buffer overflow in fig2dev/read.c in function read_objects
fig2dev: Global buffer overflow in fig2dev/read.c in function read_objects
An Out of Bounds flaw was found fig2dev version 3.2.8a. A flawed bounds check in read_objects() could allow an attacker to provide a crafted malicious input causing the application to either crash or in some cases cause memory corruption. The highest threat from this vulnerability is to integrity as well as system availability.
An Out of Bounds flaw was found in fig2dev utility within transfig. An attacker could use this flaw and provide a crafted input to read_objects() probably resulting in a crash or in some cases memory corruption. The highest threat from this vulnerability is to integrity as well as system availability.
Package: transfig (Red Hat Enterprise Linux 6) - Not affected
Package: xfig (Red Hat Ent
Debian
CVE-2021-3561: fig2dev - An Out of Bounds flaw was found fig2dev version 3.2.8a. A flawed bounds check in...
vendor_debian·2021·CVSS 7.1
CVE-2021-3561 [HIGH] CVE-2021-3561: fig2dev - An Out of Bounds flaw was found fig2dev version 3.2.8a. A flawed bounds check in...
An Out of Bounds flaw was found fig2dev version 3.2.8a. A flawed bounds check in read_objects() could allow an attacker to provide a crafted malicious input causing the application to either crash or in some cases cause memory corruption. The highest threat from this vulnerability is to integrity as well as system availability.
Scope: local
bookworm: resolved (fixed in 1:3.2.8-3)
bullseye: resolved (fixed in 1:3.2.8-3)
forky: resolved (fixed in 1:3.2.8-3)
sid: resolved (fixed in 1:3.2.8-3)
trixie: resolved (fixed in 1:3.2.8-3)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugzilla.redhat.com/show_bug.cgi?id=1955675https://lists.debian.org/debian-lts-announce/2021/10/msg00002.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/C44WSY5KAQXC3Y2NMSVXXZS3M5U5U2E6/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JKMOIQX6GULVSYXLYW5JQY6KJNTWV3E4/https://sourceforge.net/p/mcj/fig2dev/ci/6827c09d2d6491cb2ae3ac7196439ff3aa791fd9/https://sourceforge.net/p/mcj/tickets/116/https://bugzilla.redhat.com/show_bug.cgi?id=1955675https://lists.debian.org/debian-lts-announce/2021/10/msg00002.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/C44WSY5KAQXC3Y2NMSVXXZS3M5U5U2E6/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JKMOIQX6GULVSYXLYW5JQY6KJNTWV3E4/https://sourceforge.net/p/mcj/fig2dev/ci/6827c09d2d6491cb2ae3ac7196439ff3aa791fd9/https://sourceforge.net/p/mcj/tickets/116/
2021-05-26
Published