CVE-2025-46400

Name
CVE-2025-46400
Description
In xfig diagramming tool, a segmentation fault while running fig2dev allows an attacker to availability via local input manipulation via read_arcobject function.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
secalert@redhat.com https://sourceforge.net/p/mcj/tickets/187/
vdb-entry https://access.redhat.com/security/cve/CVE-2025-46400
issue-tracking https://bugzilla.redhat.com/show_bug.cgi?id=2362054
af854a3a-2127-422b-91ae-364da2661108 https://lists.debian.org/debian-lts-announce/2025/04/msg00043.html

Match rules

CPE URI Source package Min version Max version
shopxo >= 0 <= 3.2.9a
cpe:2.3:a:fig2dev_project:fig2dev:3.2.9a:*:*:*:*:*:*:* fig2dev == None == 3.2.9a

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
fig2dev edge-community 3.2.9a-r1 mio <miyopan@e.email> possibly vulnerable
fig2dev edge-community 3.2.9a-r0 mio <miyopan@e.email> possibly vulnerable
fig2dev 3.23-community 3.2.9a-r1 mio <miyopan@e.email> possibly vulnerable
fig2dev 3.22-community 3.2.9a-r0 mio <miyopan@e.email> possibly vulnerable