PT-2025-13563 · Xfig+4 · Xfig+4

Published

2025-03-28

·

Updated

2025-10-21

·

CVE-2025-31163

CVSS v3.1

6.6

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H
Name of the Vulnerable Software and Affected Versions xfig fig2dev version 3.2.9a
Description The issue is related to a segmentation fault in the fig2dev component of xfig, which can be triggered by manipulating local input via the put patternarc function. This can lead to a null pointer dereference, potentially allowing an attacker to impact availability.
Recommendations For xfig fig2dev version 3.2.9a, consider restricting the use of the put patternarc function until a patch is available to prevent potential exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

CVE-2025-31163
DLA-4134-1
MGASA-2025-0152
OESA-2025-1366
OESA-2025-1367
OESA-2025-1368
OESA-2025-1406
OESA-2025-1407
OPENSUSE-SU-2025:15064-1
SUSE-SU-2025:01835-1
SUSE-SU-2025:01835-2
SUSE-SU-2025:1540-1
USN-7587-1

Affected Products

Debian
Linuxmint
Suse
Ubuntu
Xfig