Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Buffer overflows in Dia XFig import |
|---|---|
| Date: | 29 Mar 2006 21:27:42 -0000 |
A security review kindly performed by infamous41md has turned up three buffer overflow vulnerabilities in the XFig import plug-in in Dia, a diagramming tool for Gtk that runs on both Winddows and Unix. While the XFig format is not the native format of Dia, a specially crafted XFig file could cause arbitrary code execution *if* loaded into Dia. The vulnerabilities affect versions 0.87 through 0.94 as well as prereleases 1-5 of 0.95, after which it is fixed in the source and later prereleases. A patch against the 0.94 release has been attached to the announcement on the dia-list at http://mail.gnome.org/archives/dia-list/2006-March/msg00149.html -Lars Clausen Head Dia maintainer
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | X-Changer <=v0.2 Demo SQL injection, dabdoub-mosikar |
|---|---|
| Next by Date: | McAfee VirusScan DUNZIP32.dll Buffer Overflow Vulnerability, Juha-Matti Laurio |
| Previous by Thread: | X-Changer <=v0.2 Demo SQL injection, dabdoub-mosikar |
| Next by Thread: | McAfee VirusScan DUNZIP32.dll Buffer Overflow Vulnerability, Juha-Matti Laurio |
| Indexes: | [Date] [Thread] [Top] [All Lists] |