Revision Date: | 2022-06-30 | Version: | 1 |
Title: | CVE-2006-2480 |
Description: |
Format string vulnerability in Dia 0.94 allows user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code by triggering errors or warnings, as demonstrated via format string specifiers in a .bmp filename. NOTE: the original exploit was demonstrated through a command line argument, but there are other mechanisms for input that are automatically processed by Dia, such as a crafted .dia file.
|
Family: | unix | Class: | vulnerability |
Status: | | Reference(s): | CVE-2006-2480 Mitre CVE-2006-2480 SUSE CVE-2006-2480 SUSE-SR:2006:012
|
Platform(s): | Novell Linux Desktop 9 for x86 Novell Linux Desktop 9 for x86_64 openSUSE Tumbleweed SLES SDK 9 for IBM iSeries and IBM pSeries SLES SDK 9 for IBM S/390 and IBM zSeries SLES SDK 9 for IBM zSeries SLES SDK 9 for IPF SLES SDK 9 for x86 SLES SDK 9 for X86-64 SUSE LINUX 10.0 SUSE LINUX 10.1 SUSE LINUX 9.1 for IA32 SUSE LINUX 9.1 for x86-64 SUSE LINUX 9.2 SUSE LINUX 9.3 SuSE Linux Desktop 1.0
| Product(s): | |
Definition Synopsis |
openSUSE Tumbleweed is installed AND Package Information
dia-0.97.3-11.1 is installed
OR dia-lang-0.97.3-11.1 is installed
|