CVE-2019-18604

CRITICAL

axohelp.c < 1.3 and axodraw2 < 2.1.1 - Buffer Overflow via sprintf Mishandling

Title source: llm
STIX 2.1

Description

In axohelp.c before 1.3 in axohelp in axodraw2 before 2.1.1b, as distributed in TeXLive and other collections, sprintf is mishandled.

Scores

CVSS v3 9.8
EPSS 0.0193
EPSS Percentile 77.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

Status published
Products (2)
axodraw2_project/axodraw2 < 2.1.1
axohelp.c_project/axohelp.c < 1.3
Published Oct 29, 2019
Tracked Since Feb 18, 2026