Alerts This Week
Warning Icon 1 923
Alerts This Week
Warning Icon 1 923

Debian LTS: DLA-4134-1 critical: fig2dev heap overflow issues

debian lts
Calendar Grey April 21, 2025
Dist Debian Esm H88
Ubuntu LTS patches rectify several vulnerabilities within the fig2dev tools. Update for enhanced reliability in your operating environment.
Multiple vulnerabilities have been fixed in the fig2dev utilities for converting XFig figure files

Summary

CVE-2025-31162

floating point exception with huge pattern lengths

CVE-2025-31163

non-rejection of arcs with co-incident points

CVE-2025-31164

heap buffer overflow on arc-box with zero radius

For Debian 11 bullseye, these problems have been fixed in version
1:3.2.8-3+deb11u2.

We recommend that you upgrade your fig2dev packages.

For the detailed security status of fig2dev please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/source-package/fig2dev

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS


Severity
critical
Lowest
Low
Medium
High
Critical

Package: fig2dev
Version: 1:3.2.8-3+deb11u2
CVE ID: CVE-2025-31162 CVE-2025-31163 CVE-2025-31164

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here