CVE-2019-14275: Debian Linux
Medium severity, CVSS 5.5. EPSS: 1.2% chance of exploitation in the next 30 days.
Xfig fig2dev 3.2.7a has a stack-based buffer overflow in the calc_arrow function in bound.c.
Affected products
- Debian Debian Linux: version 8.0 only
- Opensuse Leap: version 15.1 only; version 15.2 only
- Xfig Project FIG2DEV: version 3.2.7 only
Published 2019-07-26. Last modified 2026-06-17.