An issue was discovered in fig2dev before 3.2.8.. A NULL pointer dereference exists in the function computeclosedspline() located in trans_spline.c. It allows an attacker to cause Denial of Service. The fixed version of fig2dev is 3.2.8.
{ "binaries": [ { "binary_name": "transfig", "binary_version": "1:3.2.5.e-5ubuntu0.1" } ] }
{ "binaries": [ { "binary_name": "xfig", "binary_version": "1:3.2.5.c-7" }, { "binary_name": "xfig-libs", "binary_version": "1:3.2.5.c-7" } ] }
{ "binaries": [ { "binary_name": "fig2dev", "binary_version": "1:3.2.6a-6ubuntu1.1" }, { "binary_name": "transfig", "binary_version": "1:3.2.6a-6ubuntu1.1" } ], "availability": "No subscription required" }
{ "binaries": [ { "binary_name": "fig2dev", "binary_version": "1:3.2.7a-7ubuntu0.1" } ], "availability": "No subscription required" }