CVE-2017-16899 describes an array index error in the fig2dev program within Xfig 3.2.6a, affecting Debian Linux and Xfig projects. This vulnerability, stemming from a negative font value in dev/gentikz.c and issues in read.c and read1_3.c, allows remote attackers to trigger a denial-of-service or information disclosure through a specially crafted Fig format file. Rated 7.1 HIGH on CVSS, it requires user interaction (UI:R) and local access (AV:L), with potential for high confidentiality (C:H) and availability (A:H impact). There is no evidence of active exploitation, publicly available exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.2.6aCPE matchmatch criteria | cpe:2.3:a:xfig_project:xfig:3.2.6a:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.