Описание
The rasterization process in Inkscape before 0.48.4 allows local users to read arbitrary files via an external entity in a SVG file, aka an XML external entity (XXE) injection attack.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | not-affected | 0.48.4-0ubuntu1 |
| hardy | ignored | end of life |
| lucid | released | 0.47.0-2ubuntu2.1 |
| oneiric | released | 0.48.2-0ubuntu1.1 |
| precise | released | 0.48.3.1-1ubuntu1.1 |
| quantal | released | 0.48.3.1-1ubuntu6.1 |
| upstream | released | 0.48.4 |
Показывать по
EPSS
2.1 Low
CVSS2
5.5 Medium
CVSS3
Связанные уязвимости
The rasterization process in Inkscape before 0.48.4 allows local users to read arbitrary files via an external entity in a SVG file, aka an XML external entity (XXE) injection attack.
The rasterization process in Inkscape before 0.48.4 allows local users to read arbitrary files via an external entity in a SVG file, aka an XML external entity (XXE) injection attack.
The rasterization process in Inkscape before 0.48.4 allows local users ...
The rasterization process in Inkscape before 0.48.4 allows local users to read arbitrary files via an external entity in a SVG file, aka an XML external entity (XXE) injection attack.
EPSS
2.1 Low
CVSS2
5.5 Medium
CVSS3