In axohelp.c before 1.3 in axohelp in axodraw2 before 2.1.1b, as distributed in TeXLive and other collections, sprintf is mishandled.
[
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.3"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "2.1.1"
}
]
},
{
"events": [
{
"introduced": "axohelp.c"
},
{
"fixed": "1.3"
}
]
},
{
"events": [
{
"introduced": "axodraw2"
},
{
"fixed": "2.1.1b"
}
]
}
]
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2019-18604.json"