{"id":"UBUNTU-CVE-2023-45920","details":"** DISPUTED ** Xfig v3.2.8 was discovered to contain a NULL pointer dereference when calling XGetWMHints(). NOTE: this is disputed because it is not expected that an X application should continue to run when there is arbitrary anomalous behavior from the X server or window manager.","modified":"2024-03-27T05:15:00Z","published":"2024-03-27T05:15:00Z","withdrawn":"2025-06-23T15:56:55Z","references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2023-45920"},{"type":"REPORT","url":"http://seclists.org/fulldisclosure/2024/Jan/48"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2023-45920"}],"affected":[{"package":{"name":"xfig","ecosystem":"Ubuntu:Pro:16.04:LTS","purl":"pkg:deb/ubuntu/xfig"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1:3.2.5.c-5","1:3.2.5.c-6","1:3.2.5.c-7"],"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2023/UBUNTU-CVE-2023-45920.json"}},{"package":{"name":"xfig","ecosystem":"Ubuntu:Pro:18.04:LTS","purl":"pkg:deb/ubuntu/xfig"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1:3.2.6a-1","1:3.2.6a-2"],"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2023/UBUNTU-CVE-2023-45920.json"}},{"package":{"name":"xfig","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/xfig"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1:3.2.7a-3","1:3.2.7b-1","1:3.2.7b-2"],"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2023/UBUNTU-CVE-2023-45920.json"}},{"package":{"name":"xfig","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/xfig"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1:3.2.8-3","1:3.2.8b-1"],"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2023/UBUNTU-CVE-2023-45920.json"}},{"package":{"name":"xfig","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/xfig"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1:3.2.8b-2build2","1:3.2.9-1","1:3.2.9-2","1:3.2.9-2build2","1:3.2.9-2build3"],"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2023/UBUNTU-CVE-2023-45920.json"}}],"schema_version":"1.7.3"}