CVE-2005-2966: Medium severity dia dia vulnerability
Published Oct 5, 2005
·Updated
The Python SVG import plugin (diasvgimport.py) for DIA 0.94 and earlier allows user-assisted attackers to execute arbitrary commands via a crafted SVG file.
Affected Software
4 affected components
Dia Dia=0.91
Dia Dia=0.93
Dia Dia<=0.94
Dia Dia=0.92.2
Event History
Oct 5, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-2966?
CVE-2005-2966 has a critical severity rating due to the potential for arbitrary command execution.
2
How do I fix CVE-2005-2966?
To fix CVE-2005-2966, you should update Dia to a version later than 0.94.
3
What versions of Dia are affected by CVE-2005-2966?
CVE-2005-2966 affects Dia versions 0.91, 0.92.2, 0.93, and 0.94 and earlier.
4
What type of attack does CVE-2005-2966 involve?
CVE-2005-2966 involves user-assisted attacks that exploit crafted SVG files.
5
Is there a workaround for CVE-2005-2966?
Currently, the recommended workaround for CVE-2005-2966 is to avoid opening untrusted SVG files within Dia.