7.6
CVSSv2

CVE-2006-1550

Published: 30/03/2006 Updated: 18/10/2018
CVSS v2 Base Score: 7.6 | Impact Score: 10 | Exploitability Score: 4.9
VMScore: 676
Vector: AV:N/AC:H/Au:N/C:C/I:C/A:C

Vulnerability Summary

Multiple buffer overflows in the xfig import code (xfig-import.c) in Dia 0.87 and later prior to 0.95-pre6 allow user-assisted malicious users to have an unknown impact via a crafted xfig file, possibly involving an invalid (1) color index, (2) number of points, or (3) depth.

Vulnerable Product Search on Vulmon Subscribe to Product

dia dia 0.91

dia dia 0.92.2

dia dia 0.87

dia dia 0.88.1

dia dia 0.93

dia dia 0.94

Vendor Advisories

Three buffer overflows were discovered in the Xfig file format importer By tricking a user into opening a specially crafted fig file with dia, an attacker could exploit this to execute arbitrary code with the user’s privileges ...
Debian Bug report logs - #360566 dia: buffer overflows in xfig importer [CVE-2006-1550] Package: dia; Maintainer for dia is Rodrigo Siqueira <siqueira@imeuspbr>; Source for dia is src:dia (PTS, buildd, popcon) Reported by: Martin Pitt <mpitt@debianorg> Date: Mon, 3 Apr 2006 09:48:08 UTC Severity: grave Tags: pat ...