5.1
CVSSv2

CVE-2005-2966

Published: 05/10/2005 Updated: 03/10/2018
CVSS v2 Base Score: 5.1 | Impact Score: 6.4 | Exploitability Score: 4.9
VMScore: 454
Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P

Vulnerability Summary

The Python SVG import plugin (diasvg_import.py) for DIA 0.94 and previous versions allows user-assisted malicious users to execute arbitrary commands via a crafted SVG file.

Vulnerable Product Search on Vulmon Subscribe to Product

dia dia 0.91

dia dia 0.92.2

dia dia 0.93

dia dia

Vendor Advisories

Joxean Koret discovered that the SVG import plugin did not properly sanitise data read from an SVG file By tricking an user into opening a specially crafted SVG file, an attacker could exploit this to execute arbitrary code with the privileges of the user ...
Joxean Koret discovered that the Python SVG import plugin in dia, a vector-oriented diagram editor, does not properly sanitise data read from an SVG file and is hence vulnerable to execute arbitrary Python code The old stable distribution (woody) is not affected by this problem For the stable distribution (sarge) this problem has been fixed in ve ...