VDB

CVE-2009-4227

CVE-2009-4227 REJECTED

Stack-based buffer overflow in the read_1_3_textobject function in f_readold.c in Xfig 3.2.5b and earlier, and in the read_textobject function in read1_3.c in fig2dev in Transfig 3.2.5a and earlier, allows remote attackers to execute arbitrary code via a long string in a malformed .fig file that uses the 1.3 file format. NOTE: some of these details are obtained from third party information.

EPSS 15.00% · 94.7th percentile

Risk Scores

EPSS Score
15.00%
94.7th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSxfig0, 1:3.2.5.c-5, 1:3.2.5.c-6

Timeline

  • Dec 3, 2009 PoC Published
  • Dec 8, 2009 CVE Published
  • Feb 4, 2022 EPSS Score
  • Mar 29, 2022 EPSS Score
  • Jul 12, 2022 EPSS Score
  • Sep 4, 2022 EPSS Score
  • Oct 26, 2022 EPSS Score
  • Dec 18, 2022 EPSS Score
  • Mar 7, 2023 EPSS Score
  • Apr 3, 2023 EPSS Score
  • May 25, 2023 EPSS Score
  • Jul 17, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›