make_arrow in arrow.c in Xfig fig2dev 3.2.7b allows a segmentation fault and out-of-bounds write because of an integer overflow via a large arrow type.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
fig2dev project fig2dev 3.2.7b |
||
fedoraproject fedora 31 |
||
fedoraproject fedora 32 |