Описание
Security update for perl-Image-Info
This update for perl-Image-Info fixes the following issues:
- update to version 1.39 to fix a potential security issue. A crafted SVG file could have caused information disclosure or denial of service by using external entitity expansion (XXE). This is a potentially incompatible change; however usually SVG files do not rely on XXE. (boo#1008647, CVE-2016-9181)
Список пакетов
openSUSE Leap 42.1
perl-Image-Info-1.39-5.1
openSUSE Leap 42.2
perl-Image-Info-1.39-5.1
Ссылки
- E-Mail link for openSUSE-SU-2017:0667-1
- SUSE Security Ratings
Описание
perl-Image-Info: When parsing an SVG file, external entity expansion (XXE) was not disabled. An attacker could craft an SVG file which, when processed by an application using perl-Image-Info, could cause denial of service or, potentially, information disclosure.
Затронутые продукты
openSUSE Leap 42.1:perl-Image-Info-1.39-5.1
openSUSE Leap 42.2:perl-Image-Info-1.39-5.1
Ссылки
- CVE-2016-9181
- SUSE Bug 1008647