Format string vulnerability in Inkscape before 0.45.1 allows user-assisted remote attackers to execute arbitrary code via format string specifiers in a URI, which is not properly handled by certain dialogs.
2007-03-21T19:19:00.000
2025-04-09T00:30:58.490
Deferred
CVSSv2: 6.8 (MEDIUM)
AV:N/AC:M/Au:N/C:P/I:P/A:P
8.6
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | ubuntu | ubuntu_linux | 5.10 | No |
Operating System | ubuntu | ubuntu_linux | 6.06 | No |
Operating System | ubuntu | ubuntu_linux | 6.06_lts | No |
Operating System | ubuntu | ubuntu_linux | 6.10 | No |
Application | inkscape | inkscape | 0.40 | Yes |
Application | inkscape | inkscape | 0.41 | Yes |
Application | inkscape | inkscape | 0.42 | Yes |
Application | inkscape | inkscape | 0.42.1 | Yes |
Application | inkscape | inkscape | 0.42.2 | Yes |
Application | inkscape | inkscape | 0.43 | Yes |
Application | inkscape | inkscape | 0.44 | Yes |