Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2012-5656

Опубликовано: 17 дек. 2012
Источник: redhat
CVSS2: 5
EPSS Низкий

Описание

The rasterization process in Inkscape before 0.48.4 allows local users to read arbitrary files via an external entity in a SVG file, aka an XML external entity (XXE) injection attack.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6inkscapeWill not fix

Показывать по

Дополнительная информация

Статус:

Low
https://bugzilla.redhat.com/show_bug.cgi?id=888249inkscape: XXE via SVG rasterization

EPSS

Процентиль: 64%
0.01155
Низкий

5 Medium

CVSS2

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 13 лет назад

The rasterization process in Inkscape before 0.48.4 allows local users to read arbitrary files via an external entity in a SVG file, aka an XML external entity (XXE) injection attack.

CVSS3: 5.5
nvd
больше 13 лет назад

The rasterization process in Inkscape before 0.48.4 allows local users to read arbitrary files via an external entity in a SVG file, aka an XML external entity (XXE) injection attack.

CVSS3: 5.5
debian
больше 13 лет назад

The rasterization process in Inkscape before 0.48.4 allows local users ...

CVSS3: 5.5
github
около 4 лет назад

The rasterization process in Inkscape before 0.48.4 allows local users to read arbitrary files via an external entity in a SVG file, aka an XML external entity (XXE) injection attack.

EPSS

Процентиль: 64%
0.01155
Низкий

5 Medium

CVSS2