Описание
Security update for xmlgraphics-batik
This update for xmlgraphics-batik fixes the following issues:
- CVE-2019-17566: Fixed a SSRF which might have allowed the underlying server to make arbitrary GET requests (bsc#1172961).
This update was imported from the SUSE:SLE-15-SP1:Update update project.
Список пакетов
openSUSE Leap 15.1
xmlgraphics-batik-1.9-lp151.6.3.1
xmlgraphics-batik-demo-1.9-lp151.6.3.1
xmlgraphics-batik-rasterizer-1.9-lp151.6.3.1
xmlgraphics-batik-slideshow-1.9-lp151.6.3.1
xmlgraphics-batik-squiggle-1.9-lp151.6.3.1
xmlgraphics-batik-svgpp-1.9-lp151.6.3.1
xmlgraphics-batik-ttf2svg-1.9-lp151.6.3.1
Ссылки
- E-Mail link for openSUSE-SU-2020:0851-1
- SUSE Security Ratings
- SUSE Bug 1172961
- SUSE CVE CVE-2019-17566 page
Описание
Apache Batik is vulnerable to server-side request forgery, caused by improper input validation by the "xlink:href" attributes. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests.
Затронутые продукты
openSUSE Leap 15.1:xmlgraphics-batik-1.9-lp151.6.3.1
openSUSE Leap 15.1:xmlgraphics-batik-demo-1.9-lp151.6.3.1
openSUSE Leap 15.1:xmlgraphics-batik-rasterizer-1.9-lp151.6.3.1
openSUSE Leap 15.1:xmlgraphics-batik-slideshow-1.9-lp151.6.3.1
Ссылки
- CVE-2019-17566
- SUSE Bug 1172961