read_colordef in read.c in Xfig fig2dev 3.2.7b has an out-of-bounds write.
{ "urgency": "not yet assigned" }