A buffer underwrite in fig2dev's get_line() function can be triggered by a crafted FIG file, causing out-of-bounds writes while the program strips trailing carriage returns from input. The flaw, tracked as CVE-2018-16140, affects fig2dev 3.2.7a and stems from unsafe access to buf[len-1] and buf[len-2] when the local length variable is too small, leading to segmentation faults and sanitizer-detected memory corruption.
The issue was previously reported in Debian against fig2dev 1:3.2.6a-6, where maintainers noted the bug in read.c and later marked it fixed in 1:3.2.7-1 through input sanitization changes. Subsequent research found the vulnerability was still reproducible in later code through fuzzing, indicating the earlier remediation was incomplete; a proper fix requires bounds checks before accessing trailing buffer positions, such as validating the length before touching buf[len-2].

See affected versions and whether adversaries are exploiting it.
5 events from the most recent confirmed update back to the earliest known activity.
The buffer underwrite vulnerability in fig2dev 3.2.7a was publicly disclosed as CVE-2018-16140. The issue could be triggered with a crafted FIG file and was credited to the ACE Team at Loginsoft.
A patch release was issued for CVE-2018-16140 following vendor disclosure. The vulnerability affected fig2dev 3.2.7a's get_line() handling of short input lengths, which could trigger out-of-bounds access.
Loginsoft's ACE Team disclosed a buffer underwrite vulnerability later tracked as CVE-2018-16140 to the vendor. Their research found the issue remained reproducible in fig2dev 3.2.7a despite an earlier similar bug having been considered fixed.
Jakub Wilk reported a buffer underwrite vulnerability in fig2dev's get_line() function affecting version 1:3.2.6a-6. The bug involved out-of-bounds writes when the input length was 0 or, in some cases, 1.
Debian acknowledged bug #882022 as fixed in fig2dev version 1:3.2.7-1, noting that input sanitization in the new upstream 3.2.7 release addressed this and related issues. The closure message said the fix was included in the version headed to the Debian FTP archive.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 25 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.