First published: Tue Nov 22 2005(Updated: )
Buffer overflow in the SVG importer (style.cpp) of inkscape 0.41 through 0.42.2 might allow remote attackers to execute arbitrary code via a SVG file with long CSS style property values.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Inkscape Inkscape | =0.42.2 | |
Inkscape Inkscape | =0.41 | |
Inkscape Inkscape | =0.42.1 | |
Inkscape Inkscape | =0.42 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-3737 is classified as a critical vulnerability due to the potential for remote code execution.
To fix CVE-2005-3737, upgrade Inkscape to version 0.43 or later.
Inkscape versions 0.41 through 0.42.2 are affected by CVE-2005-3737.
CVE-2005-3737 enables remote attackers to execute arbitrary code on the affected system.
Yes, there are known exploits that take advantage of the buffer overflow vulnerability in the SVG importer.