USN-193-1: dia vulnerability
4 October 2005
dia vulnerability
Releases
Details
Joxean Koret discovered that the SVG import plugin did not properly
sanitise data read from an SVG file. By tricking an user into opening
a specially crafted SVG file, an attacker could exploit this to
execute arbitrary code with the privileges of the user.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 5.04
-
dia-common
-
In general, a standard system update will make all the necessary changes.