A vulnerability in Xfig could result in execution of arbitrary code or Denial of Service.
|Package||media-gfx/xfig on all architectures|
|Affected versions||< 3.2.5b-r1|
|Unaffected versions||>= 3.2.5b-r1|
Xfig is an interactive drawing tool.
Xfig contains a buffer overflow vulnerability in processing certain FIG images.
A remote attacker could entice a user to open a specially-crafted file, potentially resulting in arbitrary code execution or a Denial of Service condition.
There is no known workaround at this time.
All Xfig users should upgrade to the latest version:
# emerge --sync # emerge --ask --oneshot --verbose ">=media-gfx/xfig-3.2.5b-r1"
NOTE: This is a legacy GLSA. Updates for all affected architectures are available since January 09, 2011. It is likely that your system is already no longer affected by this issue.
December 27, 2013
December 27, 2013: 1