CVE-2006-2453Use of Externally-Controlled Format String in DIA

Severity
7.5HIGHNVD
EPSS
3.9%
top 11.66%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 28
Latest updateMay 1

Description

Multiple unspecified format string vulnerabilities in Dia have unspecified impact and attack vectors, a different set of issues than CVE-2006-2480.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages2 packages

debiandebian/dia< dia 0.95.0-4 (bookworm)
Debiandia/dia< 0.95.0-4+3

Patches

🔴Vulnerability Details

2
GHSA
GHSA-xh6g-prc3-64gx: Multiple unspecified format string vulnerabilities in Dia have unspecified impact and attack vectors, a different set of issues than CVE-2006-24802022-05-01
OSV
CVE-2006-2453: Multiple unspecified format string vulnerabilities in Dia have unspecified impact and attack vectors, a different set of issues than CVE-2006-24802006-05-28

📋Vendor Advisories

3
Ubuntu
Dia vulnerabilities2006-05-24
Red Hat
security flaw2006-05-06
Debian
CVE-2006-2453: dia - Multiple unspecified format string vulnerabilities in Dia have unspecified impac...2006

💬Community

4
Bugzilla
CVE-2006-2453 security flaw2018-08-16
Bugzilla
CVE-2006-2453 Additional dia format string flaws2006-05-23
Bugzilla
CVE-2006-2480 Dia format string issue (CVE-2006-2453)2006-05-22
Bugzilla
CVE-2006-2480 Dia format string issue (CVE-2006-2453)2006-05-22