make_arrow in arrow.c in Xfig fig2dev 3.2.7b allows a segmentation fault and out-of-bounds write because of an integer overflow via a large arrow type.
References
Link | Resource |
---|---|
https://sourceforge.net/p/mcj/tickets/57/ | Exploit Third Party Advisory |
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ILJM2G6NM5MMBKTT5CH23TAI6DJGNW36/ | Mailing List Third Party Advisory |
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/7XOY5NXUZ6JRBBPYA3CXWGRGQTSDVVG2/ | Mailing List Third Party Advisory |
Information
Published : 2019-12-11 19:15
Updated : 2023-02-01 18:23
NVD link : CVE-2019-19746
Mitre link : CVE-2019-19746
JSON object : View
Products Affected
fedoraproject
- fedora
fig2dev_project
- fig2dev