REDHAT-BUG-2362058: Medium severity Fig fig2dev vulnerability
Published Apr 24, 2025
·Updated
Stack-overflow in fig2dev in version 3.2.9a allows an attacker possible code execution via local input manipulation via bezierspline function.
Affected Software
1 affected component
Fig fig2dev
Event History
Apr 24, 2025
Data Sourced
via Red Hat·02:01 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of REDHAT-BUG-2362058?
REDHAT-BUG-2362058 is considered a critical vulnerability due to its potential for code execution.
2
How do I fix REDHAT-BUG-2362058?
To fix REDHAT-BUG-2362058, update to the latest version of fig2dev available from the vendor.
3
What software is affected by REDHAT-BUG-2362058?
REDHAT-BUG-2362058 affects fig2dev version 3.2.9a.
4
What is the nature of the vulnerability in REDHAT-BUG-2362058?
The vulnerability in REDHAT-BUG-2362058 is a stack overflow caused by input manipulation in the bezier_spline function.
5
Can REDHAT-BUG-2362058 be exploited remotely?
No, REDHAT-BUG-2362058 requires local input manipulation, making remote exploitation unlikely.