Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-16899

Опубликовано: 20 нояб. 2017
Источник: redhat
CVSS3: 3.3
EPSS Низкий

Описание

An array index error in the fig2dev program in Xfig 3.2.6a allows remote attackers to cause a denial-of-service attack or information disclosure with a maliciously crafted Fig format file, related to a negative font value in dev/gentikz.c, and the read_textobject functions in read.c and read1_3.c.

An out-of-bounds read flaw was found in the way fig2dev program in Xfig handled the processing of Fig format files. This flaw could potentially be used to crash the fig2dev program by tricking it into processing specially crafted Fig format files.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5transfigWill not fix
Red Hat Enterprise Linux 6transfigWill not fix
Red Hat Enterprise Linux 7transfigWill not fix

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=1515695transfig: Array index error in the fig2dev program

EPSS

Процентиль: 62%
0.00426
Низкий

3.3 Low

CVSS3

Связанные уязвимости

CVSS3: 7.1
ubuntu
около 8 лет назад

An array index error in the fig2dev program in Xfig 3.2.6a allows remote attackers to cause a denial-of-service attack or information disclosure with a maliciously crafted Fig format file, related to a negative font value in dev/gentikz.c, and the read_textobject functions in read.c and read1_3.c.

CVSS3: 7.1
nvd
около 8 лет назад

An array index error in the fig2dev program in Xfig 3.2.6a allows remote attackers to cause a denial-of-service attack or information disclosure with a maliciously crafted Fig format file, related to a negative font value in dev/gentikz.c, and the read_textobject functions in read.c and read1_3.c.

CVSS3: 7.1
debian
около 8 лет назад

An array index error in the fig2dev program in Xfig 3.2.6a allows remo ...

suse-cvrf
почти 8 лет назад

Security update for transfig

suse-cvrf
около 8 лет назад

Security update for transfig

EPSS

Процентиль: 62%
0.00426
Низкий

3.3 Low

CVSS3