4.3
CVSSv2

CVE-2021-32280

Published: 20/09/2021 Updated: 22/02/2023
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

An issue exists in fig2dev prior to 3.2.8.. A NULL pointer dereference exists in the function compute_closed_spline() located in trans_spline.c. It allows an malicious user to cause Denial of Service. The fixed version of fig2dev is 3.2.8.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

xfig project fig2dev

debian debian linux 9.0

debian debian linux 10.0

Vendor Advisories

A global buffer overflow in the genmp_writefontmacro_latex component in genmpc of fig2dev 327b allows attackers to cause a denial of service (DOS) via converting a xfig file into mp format (CVE-2020-21678) A global buffer overflow in the set_color component in gengec of fig2dev 327b allows attackers to cause a denial of service (DOS) via con ...