CVE-2021-37530: Medium severity fig2dev vulnerability
Published Jan 12, 2022
·Updated
A denial of service vulnerabiity exists in fig2dev through 3.28a due to a segfault in the openstream function in readpics.c.
Affected Software
4 affected components
Fig2dev Project Fig2dev<=3.2.8a
Debian Debian Linux=9.0
Debian Debian Linux=10.0
Debian Debian Linux=11.0
Remediation
Patch Available
Event History
Jan 12, 2022
CVE Published
via MITRE·08:18 PM
Data Sourced
via MITRE·08:18 PM
Description
Frequently Asked Questions
1
What is CVE-2021-37530?
CVE-2021-37530 is a denial of service vulnerability in fig2dev through 3.28a.
2
What is the severity of CVE-2021-37530?
The severity of CVE-2021-37530 is medium with a CVSS score of 5.5.
3
Which software versions are affected by CVE-2021-37530?
Fig2dev versions up to and including 3.28a, Debian Linux version 9.0, Debian Linux version 10.0, and Debian Linux version 11.0 are affected by CVE-2021-37530.
4
How does CVE-2021-37530 cause a denial of service?
CVE-2021-37530 causes a denial of service through a segfault in the open_stream function in readpics.c.
5
Is there a fix available for CVE-2021-37530?
At the moment, there is no known fix available for CVE-2021-37530. It is recommended to follow the recommendations provided in the reference link.