First published: Mon Sep 20 2021(Updated: )
An issue was discovered in fig2dev before 3.2.8.. A NULL pointer dereference exists in the function compute_closed_spline() located in trans_spline.c. It allows an attacker to cause Denial of Service. The fixed version of fig2dev is 3.2.8.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
fig2dev | <3.2.8 | |
Debian GNU/Linux | =9.0 | |
Debian GNU/Linux | =10.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-32280.
The severity of CVE-2021-32280 is medium with a CVSS score of 5.5.
An attacker can exploit CVE-2021-32280 by causing a Denial of Service (DoS) through a NULL pointer dereference.
The affected software versions are fig2dev before 3.2.8, Debian Linux 9.0, and Debian Linux 10.0.
To fix CVE-2021-32280, update to version 3.2.8 or newer of fig2dev.