Описание
The rasterization process in Inkscape before 0.48.4 allows local users to read arbitrary files via an external entity in a SVG file, aka an XML external entity (XXE) injection attack.
Ссылки
- Patch
- Mailing List
- Mailing List
- Mailing List
- Mailing List
- Mailing List
- ExploitMailing List
- Broken LinkThird Party AdvisoryVDB Entry
- Third Party Advisory
- ExploitIssue Tracking
- Product
- Patch
- Mailing List
- Mailing List
- Mailing List
- Mailing List
- Mailing List
- ExploitMailing List
- Broken LinkThird Party AdvisoryVDB Entry
- Third Party Advisory
Уязвимые конфигурации
Одно из
Одно из
Одно из
EPSS
5.5 Medium
CVSS3
2.1 Low
CVSS2
Дефекты
Связанные уязвимости
The rasterization process in Inkscape before 0.48.4 allows local users to read arbitrary files via an external entity in a SVG file, aka an XML external entity (XXE) injection attack.
The rasterization process in Inkscape before 0.48.4 allows local users to read arbitrary files via an external entity in a SVG file, aka an XML external entity (XXE) injection attack.
The rasterization process in Inkscape before 0.48.4 allows local users ...
The rasterization process in Inkscape before 0.48.4 allows local users to read arbitrary files via an external entity in a SVG file, aka an XML external entity (XXE) injection attack.
EPSS
5.5 Medium
CVSS3
2.1 Low
CVSS2