CVE-2019-14275: Buffer Overflow
Xfig fig2dev 3.2.7a has a stack-based buffer overflow in the calcarrow function in bound.c.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-14275?
CVE-2019-14275 is a vulnerability in Xfig fig2dev 3.2.7a that allows a stack-based buffer overflow in the calc_arrow function in bound.c.
What is the severity of CVE-2019-14275?
The severity of CVE-2019-14275 is medium, with a severity value of 5.5.
Which software is affected by CVE-2019-14275?
Xfig fig2dev 3.2.7a, Debian Linux 8.0, openSUSE Leap 15.1, and openSUSE Leap 15.2 are affected by CVE-2019-14275.
How can I fix CVE-2019-14275?
To fix CVE-2019-14275, update Xfig fig2dev to version 3.2.8 or newer, or apply the necessary patches.
Where can I find more information about CVE-2019-14275?
You can find more information about CVE-2019-14275 at the following references: [1](http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00043.html), [2](http://lists.opensuse.org/opensuse-security-announce/2020-11/msg00019.html), [3](https://lists.debian.org/debian-lts-announce/2020/01/msg00018.html).