Endless Loop Vulnerability in GNOME Dia Affecting Specific Linux Distributions
CVE-2019-19451
5.5MEDIUM
What is CVE-2019-19451?
A vulnerability in GNOME Dia allows the application to enter an endless loop when opened with an invalid filename argument. This occurs in versions prior to 2019-11-27. Essentially, during this process, Dia continuously writes output to stdout. If triggered by a thumbnailer service, this output can be directed to the system's logging facility, potentially under elevated privileges. This may lead to a scenario where the disk gets filled up over time, ultimately causing the system to become unresponsive, especially when a nonexistent file is specified.