Name | CVE-2006-1550 |
Description | Multiple buffer overflows in the xfig import code (xfig-import.c) in Dia 0.87 and later before 0.95-pre6 allow user-assisted attackers to have an unknown impact via a crafted xfig file, possibly involving an invalid (1) color index, (2) number of points, or (3) depth. |
Source | CVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
References | DSA-1025-1 |
Debian Bugs | 360566 |
The table below lists information on source packages.
Source Package | Release | Version | Status |
---|---|---|---|
dia (PTS) | bullseye | 0.97.3+git20160930-9 | fixed |
bookworm | 0.97.3+git20220525-5 | fixed | |
sid, trixie | 0.98+git20250126-1 | fixed |
The information below is based on the following data on fixed versions.
Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
---|---|---|---|---|---|---|
dia | source | woody | 0.88.1-3woody1 | DSA-1025-1 | ||
dia | source | sarge | 0.94.0-7sarge3 | DSA-1025-1 | ||
dia | source | (unstable) | 0.94.0-18 | 360566 |