The rasterization process in Inkscape before 0.48.4 allows local users to read arbitrary files via an external entity in a SVG file, aka an XML external entity (XXE) injection attack.
2013-01-18T11:48:40.323
2025-04-11T00:51:21.963
Deferred
CVSSv3.1: 5.5 (MEDIUM)
AV:L/AC:L/Au:N/C:P/I:N/A:N
3.9
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | inkscape | inkscape | < 0.48.4 | Yes |
Operating System | fedoraproject | fedora | 16 | Yes |
Operating System | fedoraproject | fedora | 17 | Yes |
Operating System | fedoraproject | fedora | 18 | Yes |
Operating System | canonical | ubuntu_linux | 10.04 | Yes |
Operating System | canonical | ubuntu_linux | 11.10 | Yes |
Operating System | canonical | ubuntu_linux | 12.04 | Yes |
Operating System | canonical | ubuntu_linux | 12.10 | Yes |
Operating System | opensuse | opensuse | 11.4 | Yes |
Operating System | opensuse | opensuse | 12.1 | Yes |
Operating System | opensuse | opensuse | 12.2 | Yes |