Source: dia
X-Debbugs-CC: [email protected]
Severity: important
Tags: security

Hi,

The following vulnerability was published for dia.

CVE-2026-77652[0]:
| A heap-based buffer overflow vulnerability exists in the Dia diagram
| editor WPG file format importer.  In plug-ins/wpg/wpg-import.c, the
| WPG import renderer allocates a fixed palette with:      ren->pPal =
| g_new0(WPGColorRGB, 256);  When handling a WPG_COLORMAP record, the
| parser reads a start index (i16) and number of colors (iNum16) from
| the file and reads palette data with:      bRet &= (iNum16 ==
| (int)fread(&ren->pPal[i16], sizeof(WPGColorRGB), iNum16, f));  The
| only bounds-related check is `if (i16 >= 0 && i16 <= iSize)`, where
| iSize is the WPG record size—not the palette capacity. There is no
| validation that i16 is less than 256 or that i16 + iNum16 does not
| exceed 256.  A malicious WPG file can supply i16=256 and iNum16=264.
| That causes fread() to write 792 bytes starting at &pPal[256], while
| the palette buffer is only 768 bytes (256 entries × 3 bytes). This
| overflows into adjacent heap metadata and can crash Dia (SIGABRT /
| malloc corruption errors) or, depending on heap layout and exploit
| primitives, potentially lead to arbitrary code execution.
| Exploitation requires convincing a user to open a crafted WPG file
| via Dia's file dialog, command line, or file association. No special
| privileges are required to deliver the file to the victim.  Affected
| component: WPG parser (plug-ins/wpg/wpg-import.c). Affected
| versions: all Dia versions containing this code path (reporter
| tested Dia 0.98+git20260221-1; issue present on upstream master as
| of 2026-08-21).

https://gitlab.gnome.org/GNOME/dia/-/issues/580


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-77652
    https://www.cve.org/CVERecord?id=CVE-2026-77652

Please adjust the affected versions in the BTS as needed.

Reply via email to