CVE-2018-16140: Canonical Ubuntu Linux
High severity, CVSS 7.8. EPSS: 1.4% chance of exploitation in the next 30 days.
A buffer underwrite vulnerability in get_line() (read.c) in fig2dev 3.2.7a allows an attacker to write prior to the beginning of the buffer via a crafted .fig file.
Affected products
- Canonical Ubuntu Linux: version 14.04 only; version 16.04 only
- FIG2DEV Project FIG2DEV: version 3.2.7a only
Published 2018-08-30. Last modified 2026-06-17.