First published: Thu Mar 30 2006(Updated: )
Multiple buffer overflows in the xfig import code (xfig-import.c) in Dia 0.87 and later before 0.95-pre6 allow user-assisted attackers to have an unknown impact via a crafted xfig file, possibly involving an invalid (1) color index, (2) number of points, or (3) depth.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Dia | =0.87 | |
Dia | =0.88.1 | |
Dia | =0.91 | |
Dia | =0.92.2 | |
Dia | =0.93 | |
Dia | =0.94 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-1550 is categorized as a moderate severity vulnerability due to the potential for buffer overflow attacks.
To mitigate CVE-2006-1550, upgrade Dia to version 0.95-pre6 or later.
CVE-2006-1550 affects Dia versions 0.87 through 0.94.
CVE-2006-1550 is a buffer overflow vulnerability in the xfig import code of Dia.
CVE-2006-1550 requires user interaction, such as opening a crafted xfig file, for exploitation.