Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2009-4227

Stack-based buffer overflow in the read_1_3_textobject function in f_readold.c in Xfig 3.2.5b and earlier, and in the read_textobject function in read1_3.c in fig2dev in Transfig 3.2.5a and earlier, allows remote attackers to execute arbitrary code via a long string in a malformed .fig file that uses the 1.3 file format. NOTE: some of these details are obtained from third party information.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.17
EPSS Ranking 94.7%
CVSS Severity
CVSS v2 Score 6.8
References
Products affected by CVE-2009-4227
  • Xfig » Xfig » Version: Any
    cpe:2.3:a:xfig:xfig:*
  • Xfig » Xfig » Version: 3.2.5
    cpe:2.3:a:xfig:xfig:3.2.5


Contact Us

Shodan ® - All rights reserved