Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 521
Alerts This Week
Warning Icon 1 521

Gentoo: GLSA 200510-06 Normal: Dia SVG Import Code Execution

gentoo
Calendar Grey October 6, 2005
Scroller Gentoo
Gentoo Security Advisory GLSA 202310-04 reveals a vulnerability in GIMP; all users are advised to update immediately.
Improperly sanitised data in Dia allows remote attackers to execute arbitrary code.

Summary

Gentoo Linux Security Advisory GLSA 200510-06 https://security.gentoo.org/ Severity: Normal Title: Dia: Arbitrary code execution through SVG import Date: October 06, 2005 Bugs: #107916 ID: 200510-06

Synopsis ======= Improperly sanitised data in Dia allows remote attackers to execute arbitrary code.
Background ========= Dia is a gtk+ based diagram creation program released under the GPL license.
Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 app-office/dia < 0.94-r3 >= 0.94-r3
========== Joxean Koret discovered that the SVG import plugin in Dia fails to properly sanitise data read from an SVG file.
Impact ===== An attacker could create a specially c...

Read the Full Advisory

Resolution

References

Availability

style>.gentoo_availability{display:block;}

Concerns

Synopsis

Background

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Affected Packages

Impact

Workaround