CVE-2021-3561: Buffer Overflow
A flaw was found in fig2dev version 3.2.8a. A global buffer overflow in fig2dev/read.c in function readobjects may lead to memory corruption and other potential consequences.
Upstream bug:
https://sourceforge.net/p/mcj/tickets/116/
Upstream fix:
https://sourceforge.net/p/mcj/fig2dev/ci/6827c09d2d6491cb2ae3ac7196439ff3aa791fd9/
Other sources
An Out of Bounds flaw was found fig2dev version 3.2.8a. A flawed bounds check in readobjects() could allow an attacker to provide a crafted malicious input causing the application to either crash or in some cases cause memory corruption. The highest threat from this vulnerability is to integrity as well as system availability.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
fig2devto a version that resolves this vulnerability.Fixed in 3.2.8aPatch Upstream fix
Event History
Frequently Asked Questions
What is CVE-2021-3561?
CVE-2021-3561 is an Out of Bounds flaw found in fig2dev version 3.2.8a.
What is the impact of CVE-2021-3561?
The highest threat from CVE-2021-3561 is to integrity, as it can cause memory corruption or application crashes.
Which software versions are affected by CVE-2021-3561?
CVE-2021-3561 affects fig2dev version 3.2.8a, Fedora versions 33 and 34, and Debian Linux version 9.0.
How can CVE-2021-3561 be exploited?
CVE-2021-3561 can be exploited by providing a crafted malicious input to the application.
Where can I find more information about CVE-2021-3561?
You can find more information about CVE-2021-3561 in the following references: [Bugzilla Red Hat](https://bugzilla.redhat.com/show_bug.cgi?id=1955675), [Debian LTS Announce](https://lists.debian.org/debian-lts-announce/2021/10/msg00002.html), [Fedora Project](https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/C44WSY5KAQXC3Y2NMSVXXZS3M5U5U2E6/).