PT-2006-1040 · Dia+1 · Dia+1

Infamous41Md

·

Published

2006-03-30

·

Updated

2018-10-18

·

CVE-2006-1550

CVSS v2.0

7.6

High

VectorAV:N/AC:H/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Dia versions 0.87 through 0.95-pre5
Description: The issue involves multiple buffer overflows in the xfig import code, potentially allowing attackers to have an unknown impact via a crafted xfig file. This could involve an invalid color index, number of points, or depth. The vulnerability may lead to a disruption in confidentiality, integrity, and availability of protected information and can be exploited remotely.
Recommendations: For Dia versions 0.87 through 0.95-pre5, update to version 0.95-pre6 or later to resolve the issue. As a temporary workaround, consider restricting the use of the xfig import feature until a patch is available. Avoid using crafted xfig files that may exploit the buffer overflows in the xfig import code.

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-07193
BDU:2015-07194
CVE-2006-1550
DSA-1025-1
RHSA-2006:0280
RHSA-2006_0280

Affected Products

Dia
Red Hat