CVE-2021-32280: Null Pointer Dereference
Published Sep 20, 2021
·Updated
An issue was discovered in fig2dev before 3.2.8.. A NULL pointer dereference exists in the function computeclosedspline() located in transspline.c. It allows an attacker to cause Denial of Service. The fixed version of fig2dev is 3.2.8.
Affected Software
3 affected components
Xfig Project Fig2dev<3.2.8
Debian Debian Linux=9.0
Debian Debian Linux=10.0
Remediation
Patch Available
Event History
Sep 20, 2021
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2021-32280.
2
What is the severity of CVE-2021-32280?
The severity of CVE-2021-32280 is medium with a CVSS score of 5.5.
3
How can an attacker exploit CVE-2021-32280?
An attacker can exploit CVE-2021-32280 by causing a Denial of Service (DoS) through a NULL pointer dereference.
4
Which software versions are affected by CVE-2021-32280?
The affected software versions are fig2dev before 3.2.8, Debian Linux 9.0, and Debian Linux 10.0.
5
How can I fix CVE-2021-32280?
To fix CVE-2021-32280, update to version 3.2.8 or newer of fig2dev.