CVE-2006-1550: Buffer Overflow
Published Mar 30, 2006
·Updated
Multiple buffer overflows in the xfig import code (xfig-import.c) in Dia 0.87 and later before 0.95-pre6 allow user-assisted attackers to have an unknown impact via a crafted xfig file, possibly involving an invalid (1) color index, (2) number of points, or (3) depth.
Affected Software
6 affected components
Dia Dia=0.87
Dia Dia=0.88.1
Dia Dia=0.91
Dia Dia=0.92.2
Dia Dia=0.93
Dia Dia=0.94
Remediation
Patch Available
Event History
Mar 30, 2006
CVE Published
11:02 PM
Mar 31, 2006
CVE Published
via MITRE·04:00 AM
Data Sourced
via MITRE·04:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-1550?
CVE-2006-1550 is categorized as a moderate severity vulnerability due to the potential for buffer overflow attacks.
2
How do I fix CVE-2006-1550?
To mitigate CVE-2006-1550, upgrade Dia to version 0.95-pre6 or later.
3
What software versions are affected by CVE-2006-1550?
CVE-2006-1550 affects Dia versions 0.87 through 0.94.
4
What type of vulnerability is CVE-2006-1550?
CVE-2006-1550 is a buffer overflow vulnerability in the xfig import code of Dia.
5
Can CVE-2006-1550 be exploited remotely?
CVE-2006-1550 requires user interaction, such as opening a crafted xfig file, for exploitation.