CVE Vulnerabilities

CVE-2009-4228

Published: Dec 08, 2009 | Modified: Jan 20, 2011
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V2
4.3 MODERATE
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V3
Ubuntu
LOW

Stack consumption vulnerability in u_bound.c in Xfig 3.2.5b and earlier allows remote attackers to cause a denial of service (application crash) via a long string in a malformed .fig file that uses the 1.3 file format, possibly related to the readfp_fig function in f_read.c.

Affected Software

Name Vendor Start Version End Version
Xfig Xfig * 3.2.5b (including)
Xfig Xfig 3.2.4 (including) 3.2.4 (including)
Xfig Xfig 3.2.5 (including) 3.2.5 (including)
Xfig Ubuntu artful *
Xfig Ubuntu cosmic *
Xfig Ubuntu dapper *
Xfig Ubuntu disco *
Xfig Ubuntu eoan *
Xfig Ubuntu groovy *
Xfig Ubuntu hardy *
Xfig Ubuntu intrepid *
Xfig Ubuntu jaunty *
Xfig Ubuntu karmic *
Xfig Ubuntu lucid *
Xfig Ubuntu maverick *
Xfig Ubuntu natty *
Xfig Ubuntu oneiric *
Xfig Ubuntu precise *
Xfig Ubuntu quantal *
Xfig Ubuntu raring *
Xfig Ubuntu saucy *
Xfig Ubuntu trusty *
Xfig Ubuntu upstream *
Xfig Ubuntu utopic *
Xfig Ubuntu vivid *
Xfig Ubuntu wily *
Xfig Ubuntu xenial *
Xfig Ubuntu yakkety *
Xfig Ubuntu zesty *

References