Untrusted search path vulnerability in the Python plugin in Dia 0.96.1, and possibly other versions, allows local users to execute arbitrary code via a Trojan horse Python file in the current working directory, related to a vulnerability in the PySys_SetArgv function (CVE-2008-5983).
| Software | From | Fixed in |
|---|---|---|
| dia / dia | 0.96.1 | 0.96.1.x |