CVE Database
/

CVE-2006-2480

Back to search

CVE-2006-2480

Published: May 19, 2006

Modified: Aug 7, 2024

PUBLISHED

Description

Format string vulnerability in Dia 0.94 allows user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code by triggering errors or warnings, as demonstrated via format string specifiers in a .bmp filename. NOTE: the original exploit was demonstrated through a command line argument, but there are other mechanisms for input that are automatically processed by Dia, such as a crafted .dia file.

VendorProductVersions

n/a

n/a

affected
n/a

References

18078
vdb-entry
x_refsource_BID
RHSA-2006:0541
vendor-advisory
x_refsource_REDHAT
20513
third-party-advisory
x_refsource_SECUNIA
20422
third-party-advisory
x_refsource_SECUNIA
20199
third-party-advisory
x_refsource_SECUNIA
oval:org.mitre.oval:def:11224
vdb-entry
signature
x_refsource_OVAL
SUSE-SR:2006:012
vendor-advisory
x_refsource_SUSE
1016203
vdb-entry
x_refsource_SECTRACK
20254
third-party-advisory
x_refsource_SECUNIA
25699
vdb-entry
x_refsource_OSVDB
MDKSA-2006:093
vendor-advisory
x_refsource_MANDRIVA
ADV-2006-1908
vdb-entry
x_refsource_VUPEN
20339
third-party-advisory
x_refsource_SECUNIA
20060506 DIA file name handling format string
mailing-list
x_refsource_VULN-DEV
USN-286-1
vendor-advisory
x_refsource_UBUNTU
GLSA-200606-03
vendor-advisory
x_refsource_GENTOO
20457
third-party-advisory
x_refsource_SECUNIA

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now