PT-2021-6551 · Fig2Dev+4 · Fig2Dev+4

Zhouan

·

Published

2021-09-20

·

Updated

2024-06-15

·

CVE-2021-32280

CVSS v2.0

7.1

High

VectorAV:N/AC:M/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions fig2dev versions prior to 3.2.8
Description An issue exists in the compute closed spline() function located in trans spline.c, which allows an attacker to cause Denial of Service due to a NULL pointer dereference. This issue can be exploited by a remote attacker.
Recommendations For versions prior to 3.2.8, update to version 3.2.8 to resolve the issue. As a temporary workaround, consider disabling the compute closed spline() function until a patch is available.

Exploit

Fix

DoS

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-01812
CVE-2021-32280
DLA-2778-1
DLA-3304-1
OESA-2021-1395
OPENSUSE-SU-2021:1439-1
OPENSUSE-SU-2021:1458-1
OPENSUSE-SU-2021:1481-1
OPENSUSE-SU-2021:3584-1
OPENSUSE-SU-2021_1439-1
OPENSUSE-SU-2021_3584-1
OPENSUSE-SU-2024:11595-1
SUSE-SU-2021:14836-1
SUSE-SU-2021:3584-1
SUSE-SU-2021:3585-1
SUSE-SU-2021_14836-1
USN-5864-1

Affected Products

Astra Linux
Linuxmint
Suse
Ubuntu
Fig2Dev