CVE-2012-5656

T

he rasterization process in Inkscape before 0.48.4 allows local users to read arbitrary files via an external entity in a SVG file, aka an XML external entity (XXE) injection attack.

References
Link Resource
http://bazaar.launchpad.net/~inkscape.dev/inkscape/trunk/revision/11931 Patch
http://lists.fedoraproject.org/pipermail/package-announce/2012-December/095024.html Mailing List
http://lists.fedoraproject.org/pipermail/package-announce/2013-January/095380.html Mailing List
http://lists.fedoraproject.org/pipermail/package-announce/2013-January/095398.html Mailing List
http://lists.opensuse.org/opensuse-updates/2013-02/msg00041.html Mailing List
http://lists.opensuse.org/opensuse-updates/2013-02/msg00043.html Mailing List
http://www.openwall.com/lists/oss-security/2012/12/20/3 Exploit Mailing List
http://www.securityfocus.com/bid/56965 Broken Link Third Party Advisory VDB Entry
http://www.ubuntu.com/usn/USN-1712-1 Third Party Advisory
https://bugs.launchpad.net/inkscape/+bug/1025185 Exploit Issue Tracking
https://launchpad.net/inkscape/+milestone/0.48.4 Product
http://bazaar.launchpad.net/~inkscape.dev/inkscape/trunk/revision/11931 Patch
http://lists.fedoraproject.org/pipermail/package-announce/2012-December/095024.html Mailing List
http://lists.fedoraproject.org/pipermail/package-announce/2013-January/095380.html Mailing List
http://lists.fedoraproject.org/pipermail/package-announce/2013-January/095398.html Mailing List
http://lists.opensuse.org/opensuse-updates/2013-02/msg00041.html Mailing List
http://lists.opensuse.org/opensuse-updates/2013-02/msg00043.html Mailing List
http://www.openwall.com/lists/oss-security/2012/12/20/3 Exploit Mailing List
http://www.securityfocus.com/bid/56965 Broken Link Third Party Advisory VDB Entry
http://www.ubuntu.com/usn/USN-1712-1 Third Party Advisory
https://bugs.launchpad.net/inkscape/+bug/1025185 Exploit Issue Tracking
https://launchpad.net/inkscape/+milestone/0.48.4 Product
Configurations

Configuration 1 (hide)

cpe:2.3:a:inkscape:inkscape:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:fedoraproject:fedora:16:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:17:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:18:*:*:*:*:*:*:*

Configuration 3 (hide)

OR cpe:2.3:o:canonical:ubuntu_linux:10.04:*:*:*:-:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:11.10:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:-:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:12.10:*:*:*:*:*:*:*

Configuration 4 (hide)

OR cpe:2.3:o:opensuse:opensuse:11.4:*:*:*:*:*:*:*
cpe:2.3:o:opensuse:opensuse:12.1:*:*:*:*:*:*:*
cpe:2.3:o:opensuse:opensuse:12.2:*:*:*:*:*:*:*

History

21 Nov 2024, 01:45

Type Values Removed Values Added
References () http://bazaar.launchpad.net/~inkscape.dev/inkscape/trunk/revision/11931 - Patch () http://bazaar.launchpad.net/~inkscape.dev/inkscape/trunk/revision/11931 - Patch
References () http://lists.fedoraproject.org/pipermail/package-announce/2012-December/095024.html - Mailing List () http://lists.fedoraproject.org/pipermail/package-announce/2012-December/095024.html - Mailing List
References () http://lists.fedoraproject.org/pipermail/package-announce/2013-January/095380.html - Mailing List () http://lists.fedoraproject.org/pipermail/package-announce/2013-January/095380.html - Mailing List
References () http://lists.fedoraproject.org/pipermail/package-announce/2013-January/095398.html - Mailing List () http://lists.fedoraproject.org/pipermail/package-announce/2013-January/095398.html - Mailing List
References () http://lists.opensuse.org/opensuse-updates/2013-02/msg00041.html - Mailing List () http://lists.opensuse.org/opensuse-updates/2013-02/msg00041.html - Mailing List
References () http://lists.opensuse.org/opensuse-updates/2013-02/msg00043.html - Mailing List () http://lists.opensuse.org/opensuse-updates/2013-02/msg00043.html - Mailing List
References () http://www.openwall.com/lists/oss-security/2012/12/20/3 - Exploit, Mailing List () http://www.openwall.com/lists/oss-security/2012/12/20/3 - Exploit, Mailing List
References () http://www.securityfocus.com/bid/56965 - Broken Link, Third Party Advisory, VDB Entry () http://www.securityfocus.com/bid/56965 - Broken Link, Third Party Advisory, VDB Entry
References () http://www.ubuntu.com/usn/USN-1712-1 - Third Party Advisory () http://www.ubuntu.com/usn/USN-1712-1 - Third Party Advisory
References () https://bugs.launchpad.net/inkscape/+bug/1025185 - Exploit, Issue Tracking () https://bugs.launchpad.net/inkscape/+bug/1025185 - Exploit, Issue Tracking
References () https://launchpad.net/inkscape/+milestone/0.48.4 - Product () https://launchpad.net/inkscape/+milestone/0.48.4 - Product

Information

Published : 2013-01-18 11:48

Updated : 2025-04-11 00:51


NVD link : CVE-2012-5656

Mitre link : CVE-2012-5656

CVE.ORG link : CVE-2012-5656


JSON object : View

CWE
CWE-611

Improper Restriction of XML External Entity Reference