Several issues have been found in transfig, a XFig figure files converter. CVE-2018-16140 . Package : transfig Version : 1:3.2.5.e-4+deb8u2 CVE ID : CVE-2018-16140 CVE-2019-14275 CVE-2019-19555 Several issues have been found in transfig, a XFig figure files converter. CVE-2018-16140 Buffer underwrite vulnerability in get_line() allows an attacker to write prior to the beginning of the buffer via a crafted .fig file. CVE-2019-14275 Stack-based buffer overflow in the calc_arrow function in bound.c. CVE-2019-19555 Stack-based buffer overflow because of an incorrect sscanf. For Debian 8 "Jessie", these problems have been fixed in version 1:3.2.5.e-4+deb8u2. We recommend that you upgrade your transfig packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Essential patch for transfig resolves several security flaws, encompassing stack overflows and memory leaks.. transfig Security Update, Debian LTS Advisory, Buffer Overflow Fix. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.