CVE-2012-5656

The rasterization process in Inkscape before 0.48.4 allows local users to read arbitrary files via an external entity in a SVG file, aka an XML external entity (XXE) injection attack.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:inkscape:inkscape:0.48:*:*:*:*:*:*:*
cpe:2.3:a:inkscape:inkscape:0.48:pre1:*:*:*:*:*:*
cpe:2.3:a:inkscape:inkscape:0.46:*:*:*:*:*:*:*
cpe:2.3:a:inkscape:inkscape:0.45.1:*:*:*:*:*:*:*
cpe:2.3:a:inkscape:inkscape:0.40:*:*:*:*:*:*:*
cpe:2.3:a:inkscape:inkscape:0.39:*:*:*:*:*:*:*
cpe:2.3:a:inkscape:inkscape:0.48:pre0:*:*:*:*:*:*
cpe:2.3:a:inkscape:inkscape:0.47:*:*:*:*:*:*:*
cpe:2.3:a:inkscape:inkscape:0.47:pre4:*:*:*:*:*:*
cpe:2.3:a:inkscape:inkscape:0.44.1:*:*:*:*:*:*:*
cpe:2.3:a:inkscape:inkscape:0.44:*:*:*:*:*:*:*
cpe:2.3:a:inkscape:inkscape:0.42.2:*:*:*:*:*:*:*
cpe:2.3:a:inkscape:inkscape:0.47:pre0:*:*:*:*:*:*
cpe:2.3:a:inkscape:inkscape:0.37:*:*:*:*:*:*:*
cpe:2.3:a:inkscape:inkscape:0.41:*:*:*:*:*:*:*
cpe:2.3:a:inkscape:inkscape:0.47:pre2:*:*:*:*:*:*
cpe:2.3:a:inkscape:inkscape:0.42:*:*:*:*:*:*:*
cpe:2.3:a:inkscape:inkscape:0.48.3:*:*:*:*:*:*:*
cpe:2.3:a:inkscape:inkscape:0.47:pre1:*:*:*:*:*:*
cpe:2.3:a:inkscape:inkscape:0.48.2:*:*:*:*:*:*:*
cpe:2.3:a:inkscape:inkscape:0.38.1:*:*:*:*:*:*:*
cpe:2.3:a:inkscape:inkscape:*:*:*:*:*:*:*:*
cpe:2.3:a:inkscape:inkscape:0.47:pre3:*:*:*:*:*:*
cpe:2.3:a:inkscape:inkscape:0.43:*:*:*:*:*:*:*
cpe:2.3:a:inkscape:inkscape:0.48.1:*:*:*:*:*:*:*

Information

Published : 2013-01-18 03:48

Updated : 2013-03-22 20:14


NVD link : CVE-2012-5656

Mitre link : CVE-2012-5656


JSON object : View

CWE
CWE-264

Permissions, Privileges, and Access Controls

Advertisement

dedicated server usa

Products Affected

inkscape

  • inkscape