Описание
Security update for transfig
This update for transfig fixes the following issues:
Update to fig2dev version 3.2.9a
- CVE-2025-31162: Fixed a floating point exception in fig2dev in get_slope function (bsc#1240380).
- CVE-2025-31163: Fixed a segmentation fault in fig2dev in put_patternarc function (bsc#1240381).
- CVE-2025-31164: Fixed a heap buffer overflow in fig2dev in create_line_with_spline function (bsc#1240379).
- CVE-2025-46397: Fixed a stack buffer overflow in fig2dev in bezier_spline function (bsc#1243260).
- CVE-2025-46398: Fixed a stack buffer overflow in fig2dev in read_objects function (bsc#1243262).
- CVE-2025-46399: Fixed a segmentation fault in fig2dev in genge_itp_spline function (bsc#1243263).
- CVE-2025-46400: Fixed a segmentation fault in fig2dev in read_arcobject function (bsc#1243261).
Список пакетов
SUSE Linux Enterprise Module for Package Hub 15 SP6
SUSE Linux Enterprise Workstation Extension 15 SP6
openSUSE Leap 15.6
Ссылки
- Link for SUSE-SU-2025:01835-1
- E-Mail link for SUSE-SU-2025:01835-1
- SUSE Security Ratings
- SUSE Bug 1225947
- SUSE Bug 1230427
- SUSE Bug 1240379
- SUSE Bug 1240380
- SUSE Bug 1240381
- SUSE Bug 1243260
- SUSE Bug 1243261
- SUSE Bug 1243262
- SUSE Bug 1243263
- SUSE CVE CVE-2025-31162 page
- SUSE CVE CVE-2025-31163 page
- SUSE CVE CVE-2025-31164 page
- SUSE CVE CVE-2025-46397 page
- SUSE CVE CVE-2025-46398 page
- SUSE CVE CVE-2025-46399 page
- SUSE CVE CVE-2025-46400 page
Описание
Floating point exception in fig2dev in version 3.2.9a allows an attacker to availability via local input manipulation via get_slope function.
Затронутые продукты
Ссылки
- CVE-2025-31162
- SUSE Bug 1240380
Описание
Segmentation fault in fig2dev in version 3.2.9a allows an attacker to availability via local input manipulation via put_patternarc function.
Затронутые продукты
Ссылки
- CVE-2025-31163
- SUSE Bug 1240381
Описание
heap-buffer overflow in fig2dev in version 3.2.9a allows an attacker to availability via local input manipulation via create_line_with_spline.
Затронутые продукты
Ссылки
- CVE-2025-31164
- SUSE Bug 1240379
Описание
In xfig diagramming tool, a stack-overflow while running fig2dev allows memory corruption via local input manipulation at the bezier_spline function.
Затронутые продукты
Ссылки
- CVE-2025-46397
- SUSE Bug 1243260
Описание
In xfig diagramming tool, a stack-overflow while running fig2dev allows memory corruption via local input manipulation via read_objects function.
Затронутые продукты
Ссылки
- CVE-2025-46398
- SUSE Bug 1243262
Описание
In xfig diagramming tool, a segmentation fault in fig2dev allows memory corruption via local input manipulation at genge_itp_spline function.
Затронутые продукты
Ссылки
- CVE-2025-46399
- SUSE Bug 1243263
Описание
In xfig diagramming tool, a segmentation fault while running fig2dev allows an attacker to availability via local input manipulation via read_arcobject function.
Затронутые продукты
Ссылки
- CVE-2025-46400
- SUSE Bug 1243261