CVE-2020-21532: Buffer Overflow
Published Sep 16, 2021
·Updated
fig2dev 3.2.7b contains a global buffer overflow in the setfigfont function in genepic.c.
Affected Software
3 affected components
Xfig Project Fig2dev=3.2.7-b
Debian Debian Linux=9.0
Debian Debian Linux=10.0
Event History
Sep 16, 2021
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is CVE-2020-21532?
CVE-2020-21532 is a vulnerability in fig2dev 3.2.7b that allows for a global buffer overflow in the setfigfont function in genepic.c.
2
What software is affected by CVE-2020-21532?
The software affected by CVE-2020-21532 includes Xfig Project Fig2dev version 3.2.7-b and Debian Debian Linux versions 9.0 and 10.0.
3
What is the severity of CVE-2020-21532?
The severity of CVE-2020-21532 is medium with a severity value of 5.5.
4
How can I fix CVE-2020-21532?
To fix CVE-2020-21532, it is recommended to update to a patched version of fig2dev or Debian Linux when available.
5
What is the Common Weakness Enumeration (CWE) of CVE-2020-21532?
The Common Weakness Enumeration (CWE) of CVE-2020-21532 is CWE-119 and CWE-120.