CVE-2025-31162Divide By Zero in Fig2dev

Severity
6.6MEDIUMNVD
EPSS
0.1%
top 67.53%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 28
Latest updateJun 23

Description

Floating point exception in fig2dev in version 3.2.9a allows an attacker to availability via local input manipulation via get_slope function.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:HExploitability: 1.8 | Impact: 4.7

Affected Packages3 packages

Debianfig2dev_project/fig2dev< 1:3.2.8-3+deb11u2+3
CVEListV5xfig/fig2dev3.2.9a

🔴Vulnerability Details

4
OSV
fig2dev vulnerabilities2025-06-23
OSV
CVE-2025-31162: Floating point exception in fig2dev in version 32025-03-28
CVEList
fig2dev float point exception2025-03-28
GHSA
GHSA-2c99-hrrc-j3vh: Floating point exception in fig2dev in version 32025-03-28

📋Vendor Advisories

3
Ubuntu
Fig2dev vulnerabilities2025-06-23
Debian
CVE-2025-31162: fig2dev - Floating point exception in fig2dev in version 3.2.9a allows an attacker to avai...2025
Microsoft
In the standard library in Rust before 1.52.0 a double free can occur in the Vec::from_iter function if freeing the element panics.2021-04-13
CVE-2025-31162 — Divide By Zero in Xfig Fig2dev | cvebase