Path to this page:
Subject: CVS commit: pkgsrc/graphics/dia
From: Lubomir Sedlacik
Date: 2006-04-04 16:52:15
Message id: 20060404145215.666A62DA27@cvs.netbsd.org
Log Message:
Security fix for CVE-2006-1550:
"Multiple buffer overflows in the xfig import code (xfig-import.c) in Dia 0.87
and later before 0.95-pre6 allow user-complicit attackers to have an unknown
impact via a crafted xfig file, possibly involving an invalid (1) color index,
(2) number of points, or (3) depth."
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1550
http://mail.gnome.org/archives/dia-list/2006-March/msg00149.html
Fix from Dia CVS.
Files: