Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-16899

Опубликовано: 20 нояб. 2017
Источник: debian

Описание

An array index error in the fig2dev program in Xfig 3.2.6a allows remote attackers to cause a denial-of-service attack or information disclosure with a maliciously crafted Fig format file, related to a negative font value in dev/gentikz.c, and the read_textobject functions in read.c and read1_3.c.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
fig2devfixed1:3.2.6a-5package
fig2devfixed1:3.2.6a-2+deb9u1stretchpackage
transfigremovedpackage
transfigfixed1:3.2.5.e-4+deb8u1jessiepackage
transfigno-dsawheezypackage

Связанные уязвимости

CVSS3: 7.1
ubuntu
около 8 лет назад

An array index error in the fig2dev program in Xfig 3.2.6a allows remote attackers to cause a denial-of-service attack or information disclosure with a maliciously crafted Fig format file, related to a negative font value in dev/gentikz.c, and the read_textobject functions in read.c and read1_3.c.

CVSS3: 3.3
redhat
около 8 лет назад

An array index error in the fig2dev program in Xfig 3.2.6a allows remote attackers to cause a denial-of-service attack or information disclosure with a maliciously crafted Fig format file, related to a negative font value in dev/gentikz.c, and the read_textobject functions in read.c and read1_3.c.

CVSS3: 7.1
nvd
около 8 лет назад

An array index error in the fig2dev program in Xfig 3.2.6a allows remote attackers to cause a denial-of-service attack or information disclosure with a maliciously crafted Fig format file, related to a negative font value in dev/gentikz.c, and the read_textobject functions in read.c and read1_3.c.

suse-cvrf
почти 8 лет назад

Security update for transfig

suse-cvrf
около 8 лет назад

Security update for transfig