Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-32280

Опубликовано: 10 авг. 2020
Источник: redhat
CVSS3: 5.5
EPSS Низкий

Описание

An issue was discovered in fig2dev before 3.2.8.. A NULL pointer dereference exists in the function compute_closed_spline() located in trans_spline.c. It allows an attacker to cause Denial of Service. The fixed version of fig2dev is 3.2.8.

The transfig package is susceptible to a NULL pointer dereference on crafted input. While translating fig code, patterns which include incomplete closed splines lead to this software flaw. The highest threat from this vulnerability is availability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6transfigOut of support scope
Red Hat Enterprise Linux 7transfigOut of support scope

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-476
https://bugzilla.redhat.com/show_bug.cgi?id=2006516transfig: NULL pointer dereference in compute_closed_spline() in trans_spline.c

EPSS

Процентиль: 26%
0.00091
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 4 лет назад

An issue was discovered in fig2dev before 3.2.8.. A NULL pointer dereference exists in the function compute_closed_spline() located in trans_spline.c. It allows an attacker to cause Denial of Service. The fixed version of fig2dev is 3.2.8.

CVSS3: 5.5
nvd
больше 4 лет назад

An issue was discovered in fig2dev before 3.2.8.. A NULL pointer dereference exists in the function compute_closed_spline() located in trans_spline.c. It allows an attacker to cause Denial of Service. The fixed version of fig2dev is 3.2.8.

CVSS3: 5.5
debian
больше 4 лет назад

An issue was discovered in fig2dev before 3.2.8.. A NULL pointer deref ...

CVSS3: 5.5
github
больше 3 лет назад

An issue was discovered in fig2dev through 20200520. A NULL pointer dereference exists in the function compute_closed_spline() located in trans_spline.c. It allows an attacker to cause Denial of Service.

CVSS3: 6.5
fstec
больше 4 лет назад

Уязвимость функции compute_closed_spline() компонента trans_spline.c утилиты для преобразования файлов с расширением .fig Fig2dev, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 26%
0.00091
Низкий

5.5 Medium

CVSS3