Bug 7239 - [Anolis OS 23] Bugfix for CVE-2021-32280
Summary: [Anolis OS 23] Bugfix for CVE-2021-32280
Status: RESOLVED FIXED
Alias: None
Product: Anolis OS 23
Classification: Anolis OS
Component: BaseOS Packages (show other bugs) BaseOS Packages
Version: unspecified
Hardware: All Linux
: P3-Medium S3-normal
Target Milestone: ---
Assignee: happy_orange
QA Contact: bolong_tbl
URL:
Whiteboard:
Keywords: CVE
Depends on:
Blocks:
 
Reported: 2023-11-13 17:17 UTC by 小龙
Modified: 2023-11-14 11:25 UTC (History)
0 users

See Also:


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description 小龙 admin 2023-11-13 17:17:18 UTC
Description:
An issue was discovered in fig2dev before 3.2.8.. A NULL pointer dereference exists in the function compute_closed_spline() located in trans_spline.c. It allows an attacker to cause Denial of Service. The fixed version of fig2dev is 3.2.8.

Broken commit info:

Bugfix commit info:
https://sourceforge.net/p/mcj/fig2dev/ci/f17a3b8a7d54c1bc56ab92512531772a0b3ec991/
Comment 1 小龙 admin 2023-11-14 11:25:57 UTC
PR: 
https://gitee.com/src-anolis-os/transfig/pulls/2