CVE-2009-4227 describes a stack-based buffer overflow vulnerability affecting Xfig 3.2.5b and earlier, and Transfig 3.2.5a and earlier. This flaw allows remote attackers to execute arbitrary code by crafting a malicious .fig file with a long string in the 1.3 file format. The vulnerability has a CVSS score of 6.8, indicating a medium severity, and can be exploited over a network with medium attack complexity, leading to partial confidentiality, integrity, and availability impacts. While not listed on the KEV catalog or showing active exploitation, public exploit code exists on ExploitDB, and its FAUCET Risk Score is 94/100, suggesting a high potential risk despite minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 3.2.5bCPE matchmatch criteria | cpe:2.3:a:xfig:xfig:*:*:*:*:*:*:*:* | ||
3.2.5CPE matchmatch criteria | cpe:2.3:a:xfig:xfig:3.2.5:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.