PT-2021-6497 · Fig2Dev+2 · Fig2Dev+2

Suhwan Song

·

Published

2021-08-10

·

Updated

2023-02-13

·

CVE-2020-21675

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions fig2dev version 3.2.7b
Description The issue is related to a stack-based buffer overflow in the genptk text component of fig2dev, which can be exploited by converting a xfig file into ptk format. This allows a remote attacker to cause a denial of service.
Recommendations For fig2dev version 3.2.7b, consider disabling the genptk text component in genptk.c as a temporary workaround to minimize the risk of exploitation. Restrict access to converting xfig files into ptk format until a patch is available.

Exploit

Fix

DoS

Memory Corruption

Weakness Enumeration

Related Identifiers

BDU:2022-01750
CVE-2020-21675
DLA-2778-1
USN-5864-1

Affected Products

Linuxmint
Ubuntu
Fig2Dev