First published: Wed Oct 05 2005(Updated: )
The Python SVG import plugin (diasvg_import.py) for DIA 0.94 and earlier allows user-assisted attackers to execute arbitrary commands via a crafted SVG file.
Credit: security@debian.org
Affected Software | Affected Version | How to fix |
---|---|---|
Dia | =0.91 | |
Dia | =0.93 | |
Dia | <=0.94 | |
Dia | =0.92.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-2966 has a critical severity rating due to the potential for arbitrary command execution.
To fix CVE-2005-2966, you should update Dia to a version later than 0.94.
CVE-2005-2966 affects Dia versions 0.91, 0.92.2, 0.93, and 0.94 and earlier.
CVE-2005-2966 involves user-assisted attacks that exploit crafted SVG files.
Currently, the recommended workaround for CVE-2005-2966 is to avoid opening untrusted SVG files within Dia.