cve/2021/CVE-2021-3561.md
2025-09-29 21:09:30 +02:00

20 lines
960 B
Markdown

### [CVE-2021-3561](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3561)
![](https://img.shields.io/static/v1?label=Product&message=fig2dev&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=fig2dev%203.2.8a%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-119&color=brightgreen)
### Description
An Out of Bounds flaw was found fig2dev version 3.2.8a. A flawed bounds check in read_objects() could allow an attacker to provide a crafted malicious input causing the application to either crash or in some cases cause memory corruption. The highest threat from this vulnerability is to integrity as well as system availability.
### POC
#### Reference
- https://sourceforge.net/p/mcj/fig2dev/ci/6827c09d2d6491cb2ae3ac7196439ff3aa791fd9/
- https://sourceforge.net/p/mcj/tickets/116/
#### Github
- https://github.com/ARPSyndicate/cvemon
- https://github.com/MiniMangosteen/MiniMangosteen