[Full-disclosure] [ GLSA 200510-06 ] Dia: Arbitrary code execution through SVG import

From: Sune Kloppenborg Jeppesen (jaervosz_at_gentoo.org)
Date: 10/06/05

  • Next message: bkfsec: "Re: [Full-disclosure] Bigger burger roll needed"
    To: gentoo-announce@gentoo.org
    Date: Thu, 6 Oct 2005 16:56:28 +0200
    
    
    
    

    - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
    Gentoo Linux Security Advisory GLSA 200510-06
    - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
                                                http://security.gentoo.org/
    - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

      Severity: Normal
         Title: Dia: Arbitrary code execution through SVG import
          Date: October 06, 2005
          Bugs: #107916
            ID: 200510-06

    - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

    Synopsis
    ========

    Improperly sanitised data in Dia allows remote attackers to execute
    arbitrary code.

    Background
    ==========

    Dia is a gtk+ based diagram creation program released under the GPL
    license.

    Affected packages
    =================

        -------------------------------------------------------------------
         Package / Vulnerable / Unaffected
        -------------------------------------------------------------------
      1 app-office/dia < 0.94-r3 >= 0.94-r3

    Description
    ===========

    Joxean Koret discovered that the SVG import plugin in Dia fails to
    properly sanitise data read from an SVG file.

    Impact
    ======

    An attacker could create a specially crafted SVG file, which, when
    imported into Dia, could lead to the execution of arbitrary code.

    Workaround
    ==========

    There is no known workaround at this time.

    Resolution
    ==========

    All Dia users should upgrade to the latest version:

        # emerge --sync
        # emerge --ask --oneshot --verbose ">=app-office/dia-0.94-r3"

    References
    ==========

      [ 1 ] CAN-2005-2966
            http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-2966

    Availability
    ============

    This GLSA and any updates to it are available for viewing at
    the Gentoo Security Website:

      http://security.gentoo.org/glsa/glsa-200510-06.xml

    Concerns?
    =========

    Security is a primary focus of Gentoo Linux and ensuring the
    confidentiality and security of our users machines is of utmost
    importance to us. Any security concerns should be addressed to
    security@gentoo.org or alternatively, you may file a bug at
    http://bugs.gentoo.org.

    License
    =======

    Copyright 2005 Gentoo Foundation, Inc; referenced text
    belongs to its owner(s).

    The contents of this document are licensed under the
    Creative Commons - Attribution / Share Alike license.

    http://creativecommons.org/licenses/by-sa/2.0

    
    

    
    

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.grok.org.uk/full-disclosure-charter.html
    Hosted and sponsored by Secunia - http://secunia.com/



  • Next message: bkfsec: "Re: [Full-disclosure] Bigger burger roll needed"

    Relevant Pages

    • [ GLSA 200510-06 ] Dia: Arbitrary code execution through SVG import
      ... Dia is a gtk+ based diagram creation program released under the GPL ... license. ... Security is a primary focus of Gentoo Linux and ensuring the ...
      (Bugtraq)
    • [Full-disclosure] [ GLSA 200606-03 ] Dia: Format string vulnerabilities
      ... Title: Dia: Format string vulnerabilities ... Security is a primary focus of Gentoo Linux and ensuring the ...
      (Full-Disclosure)
    • [ GLSA 200606-03 ] Dia: Format string vulnerabilities
      ... Title: Dia: Format string vulnerabilities ... Security is a primary focus of Gentoo Linux and ensuring the ...
      (Bugtraq)
    • Re: NASA Security Audit
      ... Subject: NASA Security Audit ... > Diceman did a lot of work with the DOE and DIA concerning ... a guy named Jay Diceman will be the point man. ... > Expect a good assessment and concise reporting when its all done. ...
      (Security-Basics)
    • Re: Vista Lic
      ... My guess is the message is coming from a trial version of an application program like MS Office (things like Word and Excel) or from some other program. ... does the Vista license need to be renewed? ... Dia 's Muire duit ...
      (microsoft.public.windows.vista.general)

  • Quantcast