UbuntuUpdates.org

Package "fig2dev"

Name: fig2dev

Description:

Utilities for converting XFig figure files

Latest version: 1:3.2.9-4ubuntu0.1
Release: oracular (24.10)
Level: updates
Repository: universe
Homepage: https://sourceforge.net/projects/mcj/

Links


Download "fig2dev"


Other versions of "fig2dev" in Oracular

Repository Area Version
base universe 1:3.2.9-4
security universe 1:3.2.9-4ubuntu0.1

Changelog

Version: 1:3.2.9-4ubuntu0.1 2025-06-23 05:07:00 UTC

  fig2dev (1:3.2.9-4ubuntu0.1) oracular-security; urgency=medium

  * SECURITY UPDATE: Denial of Service
    - debian/patches/CVE-2025-31162.patch: Reject huge pattern lengths
    - debian/patches/CVE-2025-31163.patch: Reject arcs with co-incident
      points
    - CVE-2025-31162
    - CVE-2025-31163
  * SECURITY UPDATE: Buffer Overflow
    - debian/patches/CVE-2025-31164.patch: Allow an arc-box with zero
      radius
    - CVE-2025-31164

 -- Bruce Cable <email address hidden> Wed, 18 Jun 2025 16:03:51 +1000

CVE-2025-31162 Floating point exception in fig2dev in version 3.2.9a allows an attacker to availability via local input manipulation via get_slope function.
CVE-2025-31163 Segmentation fault in fig2dev in version 3.2.9a allows an attacker to availability via local input manipulation via put_patternarc function.
CVE-2025-31164 heap-buffer overflow in fig2dev in version 3.2.9a allows an attacker to availability via local input manipulation via  create_line_with_spline.



About   -   Send Feedback to @ubuntu_updates