PT-2025-13564 · Xfig+4 · Xfig+4

Published

2025-03-28

·

Updated

2025-10-21

·

CVE-2025-31164

CVSS v3.1

6.6

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H
Name of the Vulnerable Software and Affected Versions xfig version 3.2.9a
Description The issue is related to a heap-buffer overflow in the fig2dev component, specifically affecting the create line with spline function. This allows an attacker to impact availability via local input manipulation.
Recommendations For version 3.2.9a, as a temporary workaround, consider disabling the create line with spline function until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Heap Based Buffer Overflow

Weakness Enumeration

Related Identifiers

CVE-2025-31164
DLA-4134-1
MGASA-2025-0152
OESA-2025-1366
OESA-2025-1367
OESA-2025-1368
OESA-2025-1406
OESA-2025-1407
OPENSUSE-SU-2025:15064-1
SUSE-SU-2025:01835-1
SUSE-SU-2025:01835-2
SUSE-SU-2025:1540-1
USN-7587-1

Affected Products

Debian
Linuxmint
Suse
Ubuntu
Xfig