MEDIUM · 5.5

CVE-2020-21535

fig2dev 3.2.7b contains a segmentation fault in the gencgm_start function in gencgm.c.

Vulnerability Description

fig2dev 3.2.7b contains a segmentation fault in the gencgm_start function in gencgm.c.

CVSS Score

5.5

MEDIUM

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
Xfig ProjectFig2Dev3.2.7
DebianDebian Linux9.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2020-21535?

CVE-2020-21535 is a vulnerability with a CVSS score of 5.5 (MEDIUM). fig2dev 3.2.7b contains a segmentation fault in the gencgm_start function in gencgm.c.

How severe is CVE-2020-21535?

CVE-2020-21535 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2020-21535?

Check the references section above for vendor advisories and patch information. Affected products include: Xfig Project Fig2Dev, Debian Debian Linux.