VDB

GCVE-110-MAGEIA-2020-116

GCVE-110-MAGEIA-2020-116
Advisory Published
Vulnetix · Advisory published March 6, 2020
The updated package fixes security vulnerabilities: Xfig fig2dev 3.2.7a has a stack-based buffer overflow in the calc_arrow function in bound.c. (CVE-2019-14275) read_textobject in read.c in Xfig fig2dev 3.2.7b has a stack-based buffer overflow because of an incorrect sscanf. (CVE-2019-19555) make_arrow in arrow.c in Xfig fig2dev 3.2.7b allows a segmentation fault and out-of-bounds write because of an integer overflow via a large arrow type. (CVE-2019-19746) read_colordef in read.c in Xfig fig2dev 3.2.7b has an out-of-bounds write. (CVE-2019-19797)

Affected Products

VendorProductVersionsPlatforms
Mageiatransfig3.2.7a-3.1.mga7 (unaffected), 0 (affected), 0 (affected), 3.2.7a-3.1.mga7 (unaffected)
Mageiaexfatprogs1.0.2-1.mga7 (unaffected), 0 (affected)

Browse GCVE Records

74,147 records in the GCVE database · Updated July 21, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›