First published: Thu Dec 12 2019(Updated: )
make_arrow in arrow.c in Xfig fig2dev 3.2.7b allows a segmentation fault and out-of-bounds write because of an integer overflow via a large arrow type.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
fig2dev | =3.2.7b | |
Fedoraproject Fedora | =31 | |
Fedoraproject Fedora | =32 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2019-19746 is medium with a CVSS score of 5.5.
CVE-2019-19746 affects Xfig fig2dev version 3.2.7b.
CVE-2019-19746 can be exploited by causing a segmentation fault and out-of-bounds write through an integer overflow in the make_arrow function.
To fix CVE-2019-19746, update Xfig fig2dev to a version that is not affected by the vulnerability.
Yes, you can find references for CVE-2019-19746 at the following links: [link 1], [link 2], [link 3]