Release DateMay 22, 2009 |
Severitymedium |
ImpactSystem compromise |
DescriptionThis indicates an attack attempt against a command-execution vulnerability in GNOME Dia.The vulnerability is caused by an error when the vulnerable software handles an empty search path. It allows a remote attacker to execute arbitrary commands via sending a malcious zip file. |
Affected ProductsDia 0.96.1 |
Recommended ActionsUpgrade to Dia 0.96.1-7.1 |
Coverage IPS
VCM |
Common Vulnerabilities and Exposures (CVE)CVE-2009-0314CVE-2008-5984 |
Reference/shttp://www.securityfocus.com/bid/33448 (BugTraq)http://www.securityfocus.com/bid/33445 (BugTraq) |