CVE-2017-16899: Out-of-bounds Read
An array index error in the fig2dev program in Xfig 3.2.6a allows remote attackers to cause a denial-of-service attack or information disclosure with a maliciously crafted Fig format file, related to a negative font value in dev/gentikz.c, and the readtextobject functions in read.c and read13.c.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2017-16899?
CVE-2017-16899 is a vulnerability in the fig2dev program in Xfig 3.2.6a.
How does CVE-2017-16899 impact Xfig?
CVE-2017-16899 allows remote attackers to cause a denial-of-service attack or information disclosure with a maliciously crafted Fig format file.
What is the severity of CVE-2017-16899?
CVE-2017-16899 has a severity rating of 7.1 (high).
How can I fix CVE-2017-16899?
To fix CVE-2017-16899, update the fig2dev package to version 1:3.2.6a-5 or later.
Are there any references for CVE-2017-16899?
Yes, you can find more information about CVE-2017-16899 at the following references: [1] https://security-tracker.debian.org/tracker/CVE-2017-16899 [2] https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=881143