Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2017:0667-1

Опубликовано: 11 мар. 2017
Источник: suse-cvrf

Описание

Security update for perl-Image-Info

This update for perl-Image-Info fixes the following issues:

  • update to version 1.39 to fix a potential security issue. A crafted SVG file could have caused information disclosure or denial of service by using external entitity expansion (XXE). This is a potentially incompatible change; however usually SVG files do not rely on XXE. (boo#1008647, CVE-2016-9181)

Список пакетов

openSUSE Leap 42.1
perl-Image-Info-1.39-5.1
openSUSE Leap 42.2
perl-Image-Info-1.39-5.1

Описание

perl-Image-Info: When parsing an SVG file, external entity expansion (XXE) was not disabled. An attacker could craft an SVG file which, when processed by an application using perl-Image-Info, could cause denial of service or, potentially, information disclosure.


Затронутые продукты
openSUSE Leap 42.1:perl-Image-Info-1.39-5.1
openSUSE Leap 42.2:perl-Image-Info-1.39-5.1

Ссылки