PT-2006-1040 · Dia+1 · Dia+1
Infamous41Md
·
Published
2006-03-30
·
Updated
2018-10-18
·
CVE-2006-1550
CVSS v2.0
7.6
High
| Vector | AV:N/AC:H/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
Dia versions 0.87 through 0.95-pre5
Description:
The issue involves multiple buffer overflows in the xfig import code, potentially allowing attackers to have an unknown impact via a crafted xfig file. This could involve an invalid
color index, number of points, or depth. The vulnerability may lead to a disruption in confidentiality, integrity, and availability of protected information and can be exploited remotely.Recommendations:
For Dia versions 0.87 through 0.95-pre5, update to version 0.95-pre6 or later to resolve the issue.
As a temporary workaround, consider restricting the use of the xfig import feature until a patch is available.
Avoid using crafted xfig files that may exploit the buffer overflows in the xfig import code.
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dia
Red Hat