Infinite loop in dia (Alpine package) - CVE-2019-19451
Published: June 25, 2020
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to infinite loop when launched with a filename argument that is not a valid codepoint in the current encoding. If this launch is from a thumbnailer service, this output will usually be written to disk via the system's logging facility (potentially with elevated privileges), thus filling up the disk and eventually rendering the system unusable.
Affected software
dia
Fedora
Opensuse
How to mitigate CVE-2019-19451
dia (Alpine package) - update to 4.2.1-3
dia (Alpine package) - update to 0.97.3-r1
dia - addressed in versions 0.97.3-16.el7, 0.97.3-16.el8, 0.97.3-16.fc32, 0.97.3-16.fc33