CVE-2020-21535: Medium severity fig2dev vulnerability
Published Sep 16, 2021
·Updated
fig2dev 3.2.7b contains a segmentation fault in the gencgmstart function in gencgm.c.
Affected Software
2 affected components
Xfig Project Fig2dev=3.2.7-b
Debian Debian Linux=9.0
Event History
Sep 16, 2021
CVE Published
via MITRE·08:28 PM
Data Sourced
via MITRE·08:28 PM
Description
Frequently Asked Questions
1
What is CVE-2020-21535?
CVE-2020-21535 is a vulnerability found in fig2dev 3.2.7b that can cause a segmentation fault in the gencgm_start function in gencgm.c.
2
What is the severity of CVE-2020-21535?
The severity of CVE-2020-21535 is medium with a CVSS score of 5.5.
3
Which software versions are affected by CVE-2020-21535?
The affected software versions are fig2dev 3.2.7b and Debian Debian Linux 9.0.
4
How can I fix CVE-2020-21535?
To fix CVE-2020-21535, it is recommended to update to a patched version of fig2dev 3.2.7b or apply the necessary updates provided by Debian Linux.
5
Where can I find more information about CVE-2020-21535?
You can find more information about CVE-2020-21535 at the following references: CWE-125, Debian LTS Announcement, and SourceForge ticket.