CVE-2025-31164: fig2dev heap-buffer overflow
Published Mar 28, 2025
·Updated
heap-buffer overflow in fig2dev in version 3.2.9a allows an attacker to availability via local input manipulation via createlinewithspline.
Affected Software
2 affected components
Fig fig2dev
Fig2dev Project Fig2dev=3.2.9a
Event History
Mar 28, 2025
CVE Published
via MITRE·06:01 PM
Data Sourced
via MITRE·06:01 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-31164?
CVE-2025-31164 has a high severity rating due to its potential to cause a heap-buffer overflow leading to denial of service.
2
How do I fix CVE-2025-31164?
To fix CVE-2025-31164, update fig2dev to the latest version where the vulnerability has been patched.
3
What software is affected by CVE-2025-31164?
CVE-2025-31164 affects fig2dev version 3.2.9a from Fig.
4
What attack vectors are associated with CVE-2025-31164?
CVE-2025-31164 can be exploited through local input manipulation to trigger the vulnerability.
5
What are the consequences of exploiting CVE-2025-31164?
Exploiting CVE-2025-31164 may lead to application crashes and service unavailability.