Bug 192535 - CVE-2006-2480: dia format string vulnerability
Summary: CVE-2006-2480: dia format string vulnerability
Keywords:
Status: CLOSED CURRENTRELEASE
Alias: None
Product: Fedora
Classification: Fedora
Component: dia
Version: 5
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Hans de Goede
QA Contact: Fedora Extras Quality Assurance
URL: http://cve.mitre.org/cgi-bin/cvename....
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2006-05-20 09:27 UTC by Ville Skyttä
Modified: 2007-11-30 22:11 UTC (History)
2 users (show)

Fixed In Version: 0.95-2
Clone Of:
Environment:
Last Closed: 2006-05-20 12:45:55 UTC
Type: ---
Embargoed:


Attachments (Terms of Use)

Description Ville Skyttä 2006-05-20 09:27:06 UTC
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2480

Reproducer in GNOME Bugzilla, appears to affect 0.95 too:
http://bugzilla.gnome.org/show_bug.cgi?id=342111

The CVE notes that this may not be a vulnerability, but it is a reproducible
crash in any case.

Comment 1 Hans de Goede 2006-05-20 12:45:55 UTC
Fixed using the patch attached to upstream's BZ (after checking / verifying it).
The fix has been imported into CVS, build and pushed for FC-5 and devel.

I assume the Security Response Team will take care of the security announcement?

And yes, this most definetly is a vulnerability. The current example of the
string format vulnerability is rather harmless, but I _think_ it will be
possbile to exploit this by getting people to open malformed files with dia.



Note You need to log in before you can comment on or make changes to this bug.