Stack-based buffer overflow in Xfig 3.2.4 and 3.2.5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a FIG image with a crafted color definition.
http://www.vupen.com/english/advisories/2011/0108
http://www.vupen.com/english/advisories/2010/3232
http://www.mandriva.com/security/advisories?name=MDVSA-2011:010