CVE-2006-2480
EPSS 7.6%
描述
Format string vulnerability in Dia 0.94 allows user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code by triggering errors or warnings, as demonstrated via format string specifiers in a .bmp filename. NOTE: the original exploit was demonstrated through a command line argument, but there are other mechanisms for input that are automatically processed by Dia, such as a crafted .dia file.
如何修補 CVE-2006-2480
要修補 CVE-2006-2480,請將受影響套件升級到下列已修補版本。
- Debian/dia—升級至 0.95.0-4 或更新版本
CVE-2006-2480 正在被利用嗎?
中等 — EPSS 為 7.6%,可持續追蹤但非最高優先。
受影響套件(1)
- from 0, < 0.95.0-4