CVE-2018-16140: High severity ubuntu vulnerability
Published Aug 29, 2018
·Updated
A buffer underwrite vulnerability in getline() (read.c) in fig2dev 3.2.7a allows an attacker to write prior to the beginning of the buffer via a crafted .fig file.
Affected Software
7 affected componentsFixes available
ubuntu/fig2dev<1:3.2.7
1:3.2.7
ubuntu/transfig<1:3.2.5.
1:3.2.5.
ubuntu/transfig<1:3.2.5.
1:3.2.5.
debian/fig2dev
1:3.2.8-3+deb11u11:3.2.8b-31:3.2.9-4
Ubuntu=14.04
Ubuntu=16.04
Fig2dev Project Fig2dev=3.2.7a
Remediation
Event History
Aug 29, 2018
CVE Published
via Ubuntu·12:00 AM
Aug 30, 2018
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Jan 11, 2024
Data Sourced
via Launchpad·10:53 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2018-16140.
2
What is the severity of CVE-2018-16140?
CVE-2018-16140 has a severity score of 7.8, which is considered high.
3
How does the vulnerability in CVE-2018-16140 occur?
The vulnerability in CVE-2018-16140 occurs due to a buffer underwrite vulnerability in get_line() in fig2dev 3.2.7a.
4
Which software versions are affected by CVE-2018-16140?
The affected software versions include fig2dev 3.2.7a-5+deb10u4, 3.2.7a-5+deb10u5, 3.2.8-3+deb11u1, 3.2.8b-3, and 3.2.9-3.
5
How can I fix CVE-2018-16140?
To fix CVE-2018-16140, you should update to the patched versions: fig2dev 3.2.7a-5+deb10u5, 3.2.8-3+deb11u1, 3.2.8b-3, or 3.2.9-3.