+++ This bug was initially created as a clone of Bug #187401 +++ Dia multiple buffer overflows infamous41md discovered three buffer overflows in Dia's xfig importer. The issues are caused by unchecked input from the xfig file. The patch can be found here: http://mail.gnome.org/archives/dia-list/2006-March/msg00149.html This issue also affects RHEL2.1 -- Additional comment from bressers on 2006-03-30 13:44 EST -- Created an attachment (id=127062) Demo Exploit #1 -- Additional comment from bressers on 2006-03-30 13:44 EST -- Created an attachment (id=127063) Demo Exploit #2 -- Additional comment from bressers on 2006-03-30 13:45 EST -- Created an attachment (id=127064) Demo Exploit #3
Many thanks for reporting this! Keep up the good work! A build (0.94-21) fixing this using the patch you linked to has been queued to the buildsys (it should build fine, I tested locally first).