PT-2025-17669 · Fig2Dev+4 · Fig2Dev+4
Liuchenyifan
·
Published
2025-02-14
·
Updated
2026-01-19
·
CVE-2025-46397
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
fig2dev version 3.2.9a
Description
The issue allows an attacker possible code execution via local input manipulation through the
bezier spline function.Recommendations
For fig2dev version 3.2.9a, consider disabling the
bezier spline function until a patch is available to prevent potential code execution via local input manipulation.Exploit
Fix
Stack Overflow
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Astra Linux
Debian
Rocky Linux
Suse
Fig2Dev