Candidate: CVE-2010-4262 PublicDate: 2010-12-17 19:00:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4262 Description: Stack-based buffer overflow in Xfig 3.2.4 and 3.2.5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a FIG image with a crafted color definition. Ubuntu-Description: Notes: Bugs: https://bugzilla.redhat.com/show_bug.cgi?id=659676 https://bugzilla.redhat.com/show_bug.cgi?id=657981 http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=606257 Priority: medium Discovered-by: Assigned-to: CVSS: Patches_xfig: upstream_xfig: released (1:3.2.5.b-1.1) dapper_xfig: ignored (reached end-of-life) hardy_xfig: ignored (reached end-of-life) karmic_xfig: ignored (reached end-of-life) lucid_xfig: ignored (reached end-of-life) maverick_xfig: ignored (reached end-of-life) natty_xfig: ignored (reached end-of-life) oneiric_xfig: ignored (reached end-of-life) precise_xfig: ignored (reached end-of-life) precise/esm_xfig: DNE (precise was needed) quantal_xfig: ignored (reached end-of-life) raring_xfig: ignored (reached end-of-life) saucy_xfig: ignored (reached end-of-life) trusty_xfig: not-affected (1:3.2.5.c-1ubuntu1) trusty/esm_xfig: DNE (trusty was not-affected [1:3.2.5.c-1ubuntu1]) utopic_xfig: ignored (reached end-of-life) vivid_xfig: ignored (reached end-of-life) vivid/stable-phone-overlay_xfig: DNE vivid/ubuntu-core_xfig: DNE wily_xfig: ignored (reached end-of-life) xenial_xfig: not-affected (1:3.2.5.c-1ubuntu1) yakkety_xfig: ignored (reached end-of-life) zesty_xfig: ignored (reached end-of-life) artful_xfig: ignored (reached end-of-life) bionic_xfig: not-affected (1:3.2.5.c-1ubuntu1) cosmic_xfig: not-affected (1:3.2.5.c-1ubuntu1) devel_xfig: not-affected (1:3.2.5.c-1ubuntu1)