6.8
CVSSv2

CVE-2010-4262

Published: 17/12/2010 Updated: 20/01/2011
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Stack-based buffer overflow in Xfig 3.2.4 and 3.2.5 allows remote malicious users to cause a denial of service (crash) and possibly execute arbitrary code via a FIG image with a crafted color definition.

Vulnerable Product Search on Vulmon Subscribe to Product

xfig xfig 3.2.5

xfig xfig 3.2.4

Vendor Advisories

Debian Bug report logs - #606257 CVE-2010-4262: Buffer overflow Package: xfig; Maintainer for xfig is Roland Rosenfeld <roland@debianorg>; Source for xfig is src:xfig (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Tue, 7 Dec 2010 21:18:01 UTC Severity: important Tags: patch, security ...