Bug 1515695 (CVE-2017-16899) - CVE-2017-16899 transfig: Array index error in the fig2dev program
Summary: CVE-2017-16899 transfig: Array index error in the fig2dev program
Keywords:
Status: CLOSED WONTFIX
Alias: CVE-2017-16899
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
low
low
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 1515696 1515697
Blocks: 1516207
TreeView+ depends on / blocked
 
Reported: 2017-11-21 09:06 UTC by Andrej Nemec
Modified: 2019-09-29 14:25 UTC (History)
8 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed: 2017-11-28 08:28:11 UTC
Embargoed:


Attachments (Terms of Use)

Description Andrej Nemec 2017-11-21 09:06:34 UTC
An array index error in the fig2dev program in Xfig 3.2.6a allows remote attackers to cause a denial-of-service attack with a maliciously crafted Fig format file, related to a negative font value in dev/gentikz.c, and the read_textobject functions in read.c and read1_3.c.

References:

https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=881143 (patch included)

Comment 1 Andrej Nemec 2017-11-21 09:07:07 UTC
Created xfig tracking bugs for this issue:

Affects: epel-7 [bug 1515696]
Affects: fedora-all [bug 1515697]


Note You need to log in before you can comment on or make changes to this bug.