5.1
CVSSv2

CVE-2006-2480

Published: 19/05/2006 Updated: 03/10/2018
CVSS v2 Base Score: 5.1 | Impact Score: 6.4 | Exploitability Score: 4.9
VMScore: 515
Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P

Vulnerability Summary

Format string vulnerability in Dia 0.94 allows user-assisted malicious users to cause a denial of service (crash) and possibly execute arbitrary code by triggering errors or warnings, as demonstrated via format string specifiers in a .bmp filename. NOTE: the original exploit was demonstrated through a command line argument, but there are other mechanisms for input that are automatically processed by Dia, such as a crafted .dia file.

Vulnerable Product Search on Vulmon Subscribe to Product

dia dia 0.94

Vendor Advisories

Debian Bug report logs - #368202 dia: CVE-2006-2480 and CVE-2006-2453: format string vulnerability Package: dia; Maintainer for dia is Rodrigo Siqueira <siqueira@imeuspbr>; Source for dia is src:dia (PTS, buildd, popcon) Reported by: Alec Berryman <alec@thenednet> Date: Sat, 20 May 2006 13:48:07 UTC Severity: gra ...
Several format string vulnerabilities have been discovered in dia By tricking a user into opening a specially crafted dia file, or a file with a specially crafted name, this could be exploited to execute arbitrary code with the user’s privileges ...

Exploits

source: wwwsecurityfocuscom/bid/18078/info Dia is prone to a remote format-string vulnerability This issue arises when the application handles specially crafted filenames An attacker can exploit this vulnerability by crafting a malicious filename that contains format specifiers and then coercing unsuspecting users to open the maliciou ...