A stack-based buffer overflow in the genptk_text component in genptk.c of fig2dev 3.2.7b allows attackers to cause a denial of service (DOS) via converting a xfig file into ptk format.
https://sourceforge.net/p/mcj/tickets/78/
https://lists.debian.org/debian-lts-announce/2021/10/msg00002.html