Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2015-0250

Опубликовано: 24 мар. 2015
Источник: debian

Описание

XML external entity (XXE) vulnerability in the SVG to (1) PNG and (2) JPG conversion classes in Apache Batik 1.x before 1.8 allows remote attackers to read arbitrary files or cause a denial of service via a crafted SVG file.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
batikfixed1.7+dfsg-5package

Примечания

  • https://issues.apache.org/jira/browse/BATIK-1018

  • https://issues.apache.org/jira/browse/BATIK-1113

  • Commit disabling external xml entities: https://svn.apache.org/viewvc/xmlgraphics/batik/trunk/sources/org/apache/batik/dom/util/SAXDocumentFactory.java?r1=662304&r2=1664335&diff_format=h

  • PoC: https://www.ernw.de/download/xxe_batik.tar.xz

Связанные уязвимости

ubuntu
почти 11 лет назад

XML external entity (XXE) vulnerability in the SVG to (1) PNG and (2) JPG conversion classes in Apache Batik 1.x before 1.8 allows remote attackers to read arbitrary files or cause a denial of service via a crafted SVG file.

redhat
больше 13 лет назад

XML external entity (XXE) vulnerability in the SVG to (1) PNG and (2) JPG conversion classes in Apache Batik 1.x before 1.8 allows remote attackers to read arbitrary files or cause a denial of service via a crafted SVG file.

nvd
почти 11 лет назад

XML external entity (XXE) vulnerability in the SVG to (1) PNG and (2) JPG conversion classes in Apache Batik 1.x before 1.8 allows remote attackers to read arbitrary files or cause a denial of service via a crafted SVG file.

github
больше 3 лет назад

Improper Input Validation in Apache Batik