CVE

CVE-2009-4228

Severity:
Pending analysis
Type:
CWE-399 Resource Management Errors
Publication date:
08/12/2009
Last modified:
20/01/2011

Description

Stack consumption vulnerability in u_bound.c in Xfig 3.2.5b and earlier allows remote attackers to cause a denial of service (application crash) via a long string in a malformed .fig file that uses the 1.3 file format, possibly related to the readfp_fig function in f_read.c.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:xfig:xfig:*:*:*:*:*:*:*:* 3.2.5b (including)
cpe:2.3:a:xfig:xfig:3.2.4:*:*:*:*:*:*:*
cpe:2.3:a:xfig:xfig:3.2.5:*:*:*:*:*:*:*