cbcvebase.
CVE-2021-3561
published 2021-05-26

CVE-2021-3561: An Out of Bounds flaw was found fig2dev version 3.2.8a. A flawed bounds check in read_objects() could allow an attacker to provide a crafted malicious input…

PriorityP428high7.1CVSS 3.1
AVLACLPRNUIRSUCNIHAH
EPSS
1.18%
64.0th percentile
An Out of Bounds flaw was found fig2dev version 3.2.8a. A flawed bounds check in read_objects() could allow an attacker to provide a crafted malicious input causing the application to either crash or in some cases cause memory corruption. The highest threat from this vulnerability is to integrity as well as system availability.

Affected

12 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianfig2dev< fig2dev 1:3.2.8-3 (bookworm)fig2dev 1:3.2.8-3 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
fig2dev_projectfig2dev
fig2dev_projectfig2dev
fig2dev_projectfig2dev>= 0 < 1:3.2.8-31:3.2.8-3
fig2dev_projectfig2dev>= 0 < 1:3.2.8-31:3.2.8-3
fig2dev_projectfig2dev>= 0 < 1:3.2.8-31:3.2.8-3
fig2dev_projectfig2dev>= 0 < 1:3.2.8-31:3.2.8-3
fig2dev_projectfig2dev>= 0 < 1:3.2.6a-6ubuntu1.11:3.2.6a-6ubuntu1.1
fig2dev_projectfig2dev>= 0 < 1:3.2.7a-7ubuntu0.11:3.2.7a-7ubuntu0.1

CVSS provenance

nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:P
osv7.1HIGH
vendor_debian7.1HIGH
vendor_redhat7.1HIGH
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.