CVE-2019-19746: Integer Overflow
Published Dec 12, 2019
·Updated
makearrow in arrow.c in Xfig fig2dev 3.2.7b allows a segmentation fault and out-of-bounds write because of an integer overflow via a large arrow type.
Affected Software
3 affected components
Fig2dev Project Fig2dev=3.2.7b
fedoraproject fedora=31
fedoraproject fedora=32
Event History
Dec 12, 2019
CVE Published
via MITRE·02:22 AM
Data Sourced
via MITRE·02:22 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-19746?
The severity of CVE-2019-19746 is medium with a CVSS score of 5.5.
2
How does CVE-2019-19746 affect Xfig fig2dev?
CVE-2019-19746 affects Xfig fig2dev version 3.2.7b.
3
How can CVE-2019-19746 be exploited?
CVE-2019-19746 can be exploited by causing a segmentation fault and out-of-bounds write through an integer overflow in the make_arrow function.
4
What is the recommended fix for CVE-2019-19746?
To fix CVE-2019-19746, update Xfig fig2dev to a version that is not affected by the vulnerability.
5
Are there any references available for CVE-2019-19746?
Yes, you can find references for CVE-2019-19746 at the following links: [link 1], [link 2], [link 3]