The Python SVG import plugin (diasvg_import.py) for DIA 0.94 and earlier allows user-assisted attackers to execute arbitrary commands via a crafted SVG file.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Dia | Dia | * | 0.94 (including) |
| Dia | Dia | 0.91 (including) | 0.91 (including) |
| Dia | Dia | 0.92.2 (including) | 0.92.2 (including) |
| Dia | Dia | 0.93 (including) | 0.93 (including) |
| Dia | Ubuntu | dapper | * |
| Dia | Ubuntu | devel | * |
| Dia | Ubuntu | edgy | * |
| Dia | Ubuntu | feisty | * |