CVE-2005-3737: Buffer Overflow
Published Nov 22, 2005
·Updated
Buffer overflow in the SVG importer (style.cpp) of inkscape 0.41 through 0.42.2 might allow remote attackers to execute arbitrary code via a SVG file with long CSS style property values.
Affected Software
4 affected components
Inkscape Inkscape=0.42.2
Inkscape Inkscape=0.41
Inkscape Inkscape=0.42.1
Inkscape Inkscape=0.42
Remediation
Patch Available
Patch Available
Event History
Nov 22, 2005
CVE Published
12:03 AM
CVE Published
via MITRE·05:00 AM
Data Sourced
via MITRE·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-3737?
CVE-2005-3737 is classified as a critical vulnerability due to the potential for remote code execution.
2
How do I fix CVE-2005-3737?
To fix CVE-2005-3737, upgrade Inkscape to version 0.43 or later.
3
What versions of Inkscape are affected by CVE-2005-3737?
Inkscape versions 0.41 through 0.42.2 are affected by CVE-2005-3737.
4
What type of attack does CVE-2005-3737 enable?
CVE-2005-3737 enables remote attackers to execute arbitrary code on the affected system.
5
Are there any known exploits for CVE-2005-3737?
Yes, there are known exploits that take advantage of the buffer overflow vulnerability in the SVG importer.