Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

DIA SVG File Import Remote Arbitrary Code Execution Vulnerability

Dia is affected by an arbitrary code-execution vulnerability.

This vulnerability presents itself when the application handles a malicious Scalable Vector Graphics (SVG) file.

A successful attack can allow remote attackers to execute arbitrary Python code in the context of the application. This may facilitate a remote compromise.

All versions of Dia are suspected to be vulnerable at the moment.







 

Privacy Statement
Copyright 2009, SecurityFocus