bugzilla.gnome.orgConfirmation
http://bugzilla.gnome.org/show_bug.cgi?id=342111 CVE-2006-2480
Dia 0.8x/0.9x - Filename Remote Format String
Record summary
CVE-2006-2480 has a selected CVSS score of 5.1; EIP currently links 1 catalogued exploit.
Description
Format string vulnerability in Dia 0.94 allows user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code by triggering errors or warnings, as demonstrated via format string specifiers in a .bmp filename. NOTE: the original exploit was demonstrated through a command line argument, but there are other mechanisms for input that are automatically processed by Dia, such as a crafted .dia file.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBDia 0.8x/0.9x - Filename Remote Format StringExploitDB exploitby KaDaL-XNot analyzed1 file
References
Showing 12 of 20kandangjamur.net
http://kandangjamur.net/tutorial/dia.txt 20199Third-party advisory
http://secunia.com/advisories/20199 20254Third-party advisory
http://secunia.com/advisories/20254 20339Third-party advisory
http://secunia.com/advisories/20339 20422Third-party advisory
http://secunia.com/advisories/20422 20457Third-party advisory
http://secunia.com/advisories/20457 20513Third-party advisory
http://secunia.com/advisories/20513 1016203vdb entry
http://securitytracker.com/id?1016203 GLSA-200606-03Vendor advisory
http://www.gentoo.org/security/en/glsa/glsa-200606-03.xml MDKSA-2006:093Vendor advisory
http://www.mandriva.com/security/advisories?name=MDKSA-2006:093 SUSE-SR:2006:012Vendor advisory
http://www.novell.com/linux/security/advisories/2006-06-02.html