CVE-2008-5984

NameCVE-2008-5984
DescriptionUntrusted search path vulnerability in the Python plugin in Dia 0.96.1, and possibly other versions, allows local users to execute arbitrary code via a Trojan horse Python file in the current working directory, related to a vulnerability in the PySys_SetArgv function (CVE-2008-5983).
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs504251

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
dia (PTS)jessie0.97.3-1fixed
stretch0.97.3+git20160930-6fixed
buster0.97.3+git20160930-8.1fixed
bullseye0.97.3+git20160930-9fixed
bookworm0.97.3+git20220525-5fixed
sid, trixie0.98+git20240814-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
diasource(unstable)0.96.1-7.1low504251

Notes

[etch] - dia <no-dsa> (Minor issue, only vulnerable when called from certain dir)

Search for package or bug name: Reporting problems