First published: Sun Dec 15 2019(Updated: )
read_colordef in read.c in Xfig fig2dev 3.2.7b has an out-of-bounds write.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
fig2dev | =3.2.7-b | |
Fedoraproject Fedora | =30 | |
Fedoraproject Fedora | =31 | |
Debian GNU/Linux | =9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-19797 is a vulnerability in Xfig fig2dev 3.2.7b that allows an out-of-bounds write in the read_colordef function in read.c.
CVE-2019-19797 has a severity rating of 5.5 (medium).
CVE-2019-19797 affects Xfig fig2dev 3.2.7b by enabling an out-of-bounds write in the read_colordef function in read.c.
To fix CVE-2019-19797 in Xfig fig2dev, you should update to version 3.2.7c or later.
Yes, here are some references for CVE-2019-19797: [Link 1](https://lists.debian.org/debian-lts-announce/2021/10/msg00002.html), [Link 2](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/7XOY5NXUZ6JRBBPYA3CXWGRGQTSDVVG2/), [Link 3](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ILJM2G6NM5MMBKTT5CH23TAI6DJGNW36/)