CVE-2020-21529: Buffer Overflow
Published Sep 16, 2021
·Updated
fig2dev 3.2.7b contains a stack buffer overflow in the bezierspline function in genepic.c.
Affected Software
3 affected components
Xfig Project Fig2dev=3.2.7-b
Debian Debian Linux=9.0
Debian Debian Linux=10.0
Event History
Sep 16, 2021
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is CVE-2020-21529?
CVE-2020-21529 is a vulnerability in fig2dev 3.2.7b that allows for a stack buffer overflow in the bezier_spline function in genepic.c.
2
What software versions are affected by CVE-2020-21529?
CVE-2020-21529 affects fig2dev version 3.2.7b.
3
How severe is CVE-2020-21529?
CVE-2020-21529 has a severity rating of medium with a CVSS score of 5.5.
4
How can I fix CVE-2020-21529?
To fix CVE-2020-21529, update fig2dev to a version that includes a patch for this vulnerability.
5
Where can I find more information about CVE-2020-21529?
You can find more information about CVE-2020-21529 at the following references: [Link 1](https://lists.debian.org/debian-lts-announce/2021/10/msg00002.html), [Link 2](https://lists.debian.org/debian-lts-announce/2023/01/msg00044.html), [Link 3](https://sourceforge.net/p/mcj/tickets/65/).