First published: Thu Sep 16 2021(Updated: )
fig2dev 3.2.7b contains a global buffer overflow in the setfigfont function in genepic.c.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
fig2dev | =3.2.7-b | |
Debian GNU/Linux | =9.0 | |
Debian GNU/Linux | =10.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-21532 is a vulnerability in fig2dev 3.2.7b that allows for a global buffer overflow in the setfigfont function in genepic.c.
The software affected by CVE-2020-21532 includes Xfig Project Fig2dev version 3.2.7-b and Debian Debian Linux versions 9.0 and 10.0.
The severity of CVE-2020-21532 is medium with a severity value of 5.5.
To fix CVE-2020-21532, it is recommended to update to a patched version of fig2dev or Debian Linux when available.
The Common Weakness Enumeration (CWE) of CVE-2020-21532 is CWE-119 and CWE-120.