make_arrow in arrow.c in Xfig fig2dev 3.2.7b allows a segmentation fault and out-of-bounds write because of an integer overflow via a large arrow type.
| Software | From | Fixed in |
|---|---|---|
| fig2dev_project / fig2dev | 3.2.7b | 3.2.7b.x |
| fedoraproject / fedora | 31 | 31.x |
| fedoraproject / fedora | 32 | 32.x |