CVE-2025-46397

Name
CVE-2025-46397
Description
A flaw was found in xfig. This vulnerability allows possible code execution via local input manipulation via bezier_spline function.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
secalert@redhat.com https://sourceforge.net/p/mcj/tickets/192/
vdb-entry https://access.redhat.com/security/cve/CVE-2025-46397
issue-tracking https://bugzilla.redhat.com/show_bug.cgi?id=2362058
af854a3a-2127-422b-91ae-364da2661108 https://lists.debian.org/debian-lts-announce/2025/04/msg00043.html
secalert@redhat.com https://access.redhat.com/errata/RHSA-2026:0700
secalert@redhat.com https://access.redhat.com/errata/RHSA-2026:0705
secalert@redhat.com https://access.redhat.com/errata/RHSA-2026:0704
secalert@redhat.com https://access.redhat.com/errata/RHSA-2026:0756

Match rules

CPE URI Source package Min version Max version
shopxo >= 0 <= 3.2.9a
cpe:2.3:a:fig2dev_project:fig2dev:3.2.9a:*:*:*:*:*:*:* fig2dev == None == 3.2.9a
cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:* enterprise_linux == None == 6.0
cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:* enterprise_linux == None == 7.0
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:* enterprise_linux == None == 8.0
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:* enterprise_linux == None == 9.0

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
fig2dev edge-community 3.2.9a-r1 mio <miyopan@e.email> possibly vulnerable
fig2dev edge-community 3.2.9a-r0 mio <miyopan@e.email> possibly vulnerable
fig2dev 3.23-community 3.2.9a-r1 mio <miyopan@e.email> possibly vulnerable
fig2dev 3.22-community 3.2.9a-r0 mio <miyopan@e.email> possibly vulnerable