CVE-2007-1463: Medium severity Ubuntu Ubuntu Linux vulnerability
Published Mar 21, 2007
·Updated
Format string vulnerability in Inkscape before 0.45.1 allows user-assisted remote attackers to execute arbitrary code via format string specifiers in a URI, which is not properly handled by certain dialogs.
Affected Software
11 affected components
Ubuntu Ubuntu Linux=5.10
Ubuntu Ubuntu Linux=6.06
Ubuntu Ubuntu Linux=6.06_lts
Ubuntu Ubuntu Linux=6.10
Inkscape Inkscape=0.40
Inkscape Inkscape=0.41
Inkscape Inkscape=0.42
Inkscape Inkscape=0.42.1
Inkscape Inkscape=0.42.2
Inkscape Inkscape=0.43
Inkscape Inkscape=0.44
Remediation
Event History
Mar 21, 2007
CVE Published
07:19 PM
Data Sourced
07:19 PM
DescriptionWeaknessAffected Software
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-1463?
CVE-2007-1463 is considered to be a medium severity vulnerability.
2
How do I fix CVE-2007-1463?
To mitigate CVE-2007-1463, upgrade Inkscape to version 0.45.1 or later.
3
What software is affected by CVE-2007-1463?
CVE-2007-1463 affects Inkscape versions prior to 0.45.1.
4
Can CVE-2007-1463 lead to remote code execution?
Yes, CVE-2007-1463 allows user-assisted remote attackers to execute arbitrary code.
5
Is Ubuntu Linux vulnerable to CVE-2007-1463?
No, specific versions of Ubuntu Linux are not vulnerable to CVE-2007-1463.