{"id":"MGASA-2017-0469","summary":"Updated transfig package fix security vulnerability","details":"An out-of-bounds read flaw was found in the way fig2dev program in Xfig\nhandled the processing of Fig format files. This flaw could potentially\nbe used to crash the fig2dev program by tricking it into processing\nspecially crafted Fig format files (CVE-2017-16899).\n","modified":"2026-04-16T06:23:01.843359171Z","published":"2017-12-25T11:16:09Z","upstream":["CVE-2017-16899"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2017-0469.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=22199"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/MCUENJQNHVYLROFSXJPDPPHHAYFYM3Z2/"}],"affected":[{"package":{"name":"transfig","ecosystem":"Mageia:5","purl":"pkg:rpm/mageia/transfig?arch=source&distro=mageia-5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.2.5d-8.1.mga5"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2017-0469.json"}},{"package":{"name":"transfig","ecosystem":"Mageia:6","purl":"pkg:rpm/mageia/transfig?arch=source&distro=mageia-6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.2.5d-9.1.mga6"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2017-0469.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}