The transfig utility creates a makefile which translates FIG (created by xfig) or PIC figures into a specified LaTeX graphics language (for example, PostScript(TM)). Transfig is used to create TeX documents which are portable (i.e., they can be printed in a wide variety of environments).
Security Fix(es):
In xfig diagramming tool, a stack-overflow while running fig2dev allows memory corruption via local input manipulation at the bezier_spline function.(CVE-2025-46397)
In xfig diagramming tool, a stack-overflow while running fig2dev allows memory corruption via local input manipulation via read_objects function.(CVE-2025-46398)
In xfig diagramming tool, a segmentation fault in fig2dev allows memory corruption via local input manipulation at gengeitpspline function.(CVE-2025-46399)
In xfig diagramming tool, a segmentation fault while running fig2dev allows an attacker to availability via local input manipulation via read_arcobject function.(CVE-2025-46400)
{ "severity": "Medium" }
{ "aarch64": [ "transfig-3.2.8b-4.oe2203sp4.aarch64.rpm", "transfig-debuginfo-3.2.8b-4.oe2203sp4.aarch64.rpm", "transfig-debugsource-3.2.8b-4.oe2203sp4.aarch64.rpm" ], "x86_64": [ "transfig-3.2.8b-4.oe2203sp4.x86_64.rpm", "transfig-debuginfo-3.2.8b-4.oe2203sp4.x86_64.rpm", "transfig-debugsource-3.2.8b-4.oe2203sp4.x86_64.rpm" ], "src": [ "transfig-3.2.8b-4.oe2203sp4.src.rpm" ], "noarch": [ "transfig-help-3.2.8b-4.oe2203sp4.noarch.rpm" ] }