Alerts This Week
Warning Icon 1 631
Alerts This Week
Warning Icon 1 631

Debian 8 LTS: DLA-2073-1 Critical Transfig Buffer Overflow Fix

debian lts
Calendar Grey January 21, 2020
Dist Debian Esm H88
Essential patch for transfig resolves several security flaws, encompassing stack overflows and memory leaks.
Several issues have been found in transfig, a XFig figure files converter

Summary

CVE-2018-16140

Buffer underwrite vulnerability in get_line()
allows an attacker to write prior to the beginning of the
buffer via a crafted .fig file.

CVE-2019-14275

Stack-based buffer overflow in the calc_arrow
function in bound.c.

CVE-2019-19555

Stack-based buffer overflow because of an
incorrect sscanf.

For Debian 8 "Jessie", these problems have been fixed in version
1:3.2.5.e-4+deb8u2.

We recommend that you upgrade your transfig packages.

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS


Severity
critical
Lowest
Low
Medium
High
Critical

Package: transfig
Version: 1:3.2.5.e-4+deb8u2
CVE ID: CVE-2018-16140 CVE-2019-14275 CVE-2019-19555

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here