CVE-2012-5656

The rasterization process in Inkscape before 0.48.4 allows local users to read arbitrary files via an external entity in a SVG file, aka an XML external entity (XXE) injection attack.
References
Link Resource
http://bazaar.launchpad.net/~inkscape.dev/inkscape/trunk/revision/11931 Patch
http://lists.fedoraproject.org/pipermail/package-announce/2012-December/095024.html Mailing List
http://lists.fedoraproject.org/pipermail/package-announce/2013-January/095380.html Mailing List
http://lists.fedoraproject.org/pipermail/package-announce/2013-January/095398.html Mailing List
http://lists.opensuse.org/opensuse-updates/2013-02/msg00041.html Mailing List
http://lists.opensuse.org/opensuse-updates/2013-02/msg00043.html Mailing List
http://www.openwall.com/lists/oss-security/2012/12/20/3 Exploit Mailing List
http://www.securityfocus.com/bid/56965 Broken Link Third Party Advisory VDB Entry
http://www.ubuntu.com/usn/USN-1712-1 Third Party Advisory
https://bugs.launchpad.net/inkscape/+bug/1025185 Exploit Issue Tracking
https://launchpad.net/inkscape/+milestone/0.48.4 Product
http://bazaar.launchpad.net/~inkscape.dev/inkscape/trunk/revision/11931 Patch
http://lists.fedoraproject.org/pipermail/package-announce/2012-December/095024.html Mailing List
http://lists.fedoraproject.org/pipermail/package-announce/2013-January/095380.html Mailing List
http://lists.fedoraproject.org/pipermail/package-announce/2013-January/095398.html Mailing List
http://lists.opensuse.org/opensuse-updates/2013-02/msg00041.html Mailing List
http://lists.opensuse.org/opensuse-updates/2013-02/msg00043.html Mailing List
http://www.openwall.com/lists/oss-security/2012/12/20/3 Exploit Mailing List
http://www.securityfocus.com/bid/56965 Broken Link Third Party Advisory VDB Entry
http://www.ubuntu.com/usn/USN-1712-1 Third Party Advisory
https://bugs.launchpad.net/inkscape/+bug/1025185 Exploit Issue Tracking
https://launchpad.net/inkscape/+milestone/0.48.4 Product
Configurations

Configuration 1 (hide)

cpe:2.3:a:inkscape:inkscape:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:fedoraproject:fedora:16:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:17:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:18:*:*:*:*:*:*:*

Configuration 3 (hide)

OR cpe:2.3:o:canonical:ubuntu_linux:10.04:*:*:*:-:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:11.10:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:-:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:12.10:*:*:*:*:*:*:*

Configuration 4 (hide)

OR cpe:2.3:o:opensuse:opensuse:11.4:*:*:*:*:*:*:*
cpe:2.3:o:opensuse:opensuse:12.1:*:*:*:*:*:*:*
cpe:2.3:o:opensuse:opensuse:12.2:*:*:*:*:*:*:*

History

No history.

Information

Published : 2013-01-18 11:48

Updated : 2025-04-11 00:51


NVD link : CVE-2012-5656

Mitre link : CVE-2012-5656

CVE.ORG link : CVE-2012-5656


JSON object : View

Products Affected

opensuse

  • opensuse

canonical

  • ubuntu_linux

inkscape

  • inkscape

fedoraproject

  • fedora
CWE
CWE-611

Improper Restriction of XML External Entity Reference