CVE-2020-21678

Related Vulnerabilities: CVE-2020-21678  

A global buffer overflow in the genmp_writefontmacro_latex component in genmp.c of fig2dev 3.2.7b allows attackers to cause a denial of service (DOS) via converting a xfig file into mp format.

Description

The MITRE CVE dictionary describes this issue as:

A global buffer overflow in the genmp_writefontmacro_latex component in genmp.c of fig2dev 3.2.7b allows attackers to cause a denial of service (DOS) via converting a xfig file into mp format.

Additional Information

  • Bugzilla 1992803: CVE-2020-21678 transfig: A global buffer overflow in the genmp_writefontmacro_latex component in genmp.c could result in a denial of service
  • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
  • FAQ: Frequently asked questions about CVE-2020-21678