In axohelp.c before 1.3 in axohelp in axodraw2 before 2.1.1b, as distributed in TeXLive and other collections, sprintf is mishandled.
{
"unresolved_ranges": [
{
"source": "CPE_FIELD",
"cpe": "cpe:2.3:a:axodraw2_project:axodraw2:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"last_affected": "2.1.1"
}
]
},
{
"source": "CPE_FIELD",
"cpe": "cpe:2.3:a:axohelp.c_project:axohelp.c:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"fixed": "1.3"
}
]
},
{
"source": "DESCRIPTION",
"extracted_events": [
{
"introduced": "axohelp.c"
},
{
"fixed": "1.3"
},
{
"introduced": "axodraw2"
},
{
"fixed": "2.1.1b"
}
]
}
]
}