CVE-2019-19746: Fedoraproject Fedora
Medium severity, CVSS 5.5. EPSS: 1.2% chance of exploitation in the next 30 days.
make_arrow in arrow.c in Xfig fig2dev 3.2.7b allows a segmentation fault and out-of-bounds write because of an integer overflow via a large arrow type.
Affected products
- Fedoraproject Fedora: version 31 only; version 32 only
- FIG2DEV Project FIG2DEV: version 3.2.7b only
Published 2019-12-12. Last modified 2026-06-17.