CVE-2025-31164

Name
CVE-2025-31164
Description
heap-buffer overflow in fig2dev in version 3.2.9a allows an attacker to availability via local input manipulation via  create_line_with_spline.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
74b3a70d-cca6-4d34-9789-e83b222ae3be https://sourceforge.net/p/mcj/tickets/184/
af854a3a-2127-422b-91ae-364da2661108 https://lists.debian.org/debian-lts-announce/2025/04/msg00030.html

Match rules

CPE URI Source package Min version Max version
fig2dev == 3.2.9a == 3.2.9a
cpe:2.3:a:fig2dev_project:fig2dev:3.2.9a:*:*:*:*:*:*:* fig2dev == None == 3.2.9a

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
fig2dev edge-community 3.2.9a-r1 mio <miyopan@e.email> possibly vulnerable
fig2dev edge-community 3.2.9a-r0 mio <miyopan@e.email> possibly vulnerable
fig2dev 3.23-community 3.2.9a-r1 mio <miyopan@e.email> possibly vulnerable
fig2dev 3.22-community 3.2.9a-r0 mio <miyopan@e.email> possibly vulnerable