USN-193-1: dia vulnerability

Ubuntu Security Notice USN-193-1

4th October, 2005

dia vulnerability

A security issue affects these releases of Ubuntu and its derivatives:

  • Ubuntu 5.04

Details

Joxean Koret discovered that the SVG import plugin did not properly
sanitise data read from an SVG file. By tricking an user into opening
a specially crafted SVG file, an attacker could exploit this to
execute arbitrary code with the privileges of the user.

Update instructions

The problem can be corrected by updating your system to the following package version:

Ubuntu 5.04:
dia-common

To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades.

None

References

CVE-2005-2966