The Python SVG import plugin (diasvg_import.py) for DIA 0.94 and earlier allows user-assisted attackers to execute arbitrary commands via a crafted SVG file.
Link | Tags |
---|---|
http://secunia.com/advisories/17059 | third party advisory vendor advisory |
http://secunia.com/advisories/17047 | third party advisory |
http://secunia.com/advisories/17095 | third party advisory vendor advisory |
http://www.debian.org/security/2005/dsa-847 | vendor advisory |
http://www.vupen.com/english/advisories/2005/1950 | vdb entry vendor advisory |
http://www.gentoo.org/security/en/glsa/glsa-200510-06.xml | vendor advisory |
http://www.debian.org/security/2006/dsa-1025 | vendor advisory |
http://www.securityfocus.com/bid/15000 | vdb entry exploit |
http://secunia.com/advisories/17083 | third party advisory vendor advisory |
http://www.mandriva.com/security/advisories?name=MDKSA-2005:187 | vendor advisory |
http://www.novell.com/linux/security/advisories/2005_22_sr.html | vendor advisory |
https://usn.ubuntu.com/193-1/ | vendor advisory |
http://secunia.com/advisories/17108 | third party advisory vendor advisory |