{
  "modified": "2025-08-09T19:01:29Z",
  "published": "2010-12-17T19:00:21Z",
  "id": "CVE-2010-4262",
  "details": "Stack-based buffer overflow in Xfig 3.2.4 and 3.2.5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a FIG image with a crafted color definition.",
  "references": [
    {
      "type": "ADVISORY",
      "url": "http://secunia.com/advisories/42579"
    },
    {
      "type": "ADVISORY",
      "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2011:010"
    },
    {
      "type": "ADVISORY",
      "url": "http://www.vupen.com/english/advisories/2010/3232"
    },
    {
      "type": "ADVISORY",
      "url": "http://www.vupen.com/english/advisories/2011/0108"
    },
    {
      "type": "EVIDENCE",
      "url": "http://lists.fedoraproject.org/pipermail/package-announce/2010-December/052247.html"
    },
    {
      "type": "EVIDENCE",
      "url": "http://www.openwall.com/lists/oss-security/2010/12/03/2"
    },
    {
      "type": "EVIDENCE",
      "url": "http://www.openwall.com/lists/oss-security/2010/12/06/8"
    },
    {
      "type": "EVIDENCE",
      "url": "http://www.securityfocus.com/bid/45177"
    },
    {
      "type": "EVIDENCE",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=657981"
    },
    {
      "type": "EVIDENCE",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=659676"
    },
    {
      "type": "FIX",
      "url": "http://lists.fedoraproject.org/pipermail/package-announce/2010-December/052247.html"
    },
    {
      "type": "FIX",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=659676"
    }
  ]
}
