CVE-2012-5656

The rasterization process in Inkscape before 0.48.4 allows local users to read arbitrary files via an external entity in a SVG file, aka an XML external entity (XXE) injection attack.
References
Link Resource
http://bazaar.launchpad.net/~inkscape.dev/inkscape/trunk/revision/11931 Patch
http://lists.fedoraproject.org/pipermail/package-announce/2012-December/095024.html Mailing List
http://lists.fedoraproject.org/pipermail/package-announce/2013-January/095380.html Mailing List
http://lists.fedoraproject.org/pipermail/package-announce/2013-January/095398.html Mailing List
http://lists.opensuse.org/opensuse-updates/2013-02/msg00041.html Mailing List
http://lists.opensuse.org/opensuse-updates/2013-02/msg00043.html Mailing List
http://www.openwall.com/lists/oss-security/2012/12/20/3 Exploit Mailing List
http://www.securityfocus.com/bid/56965 Broken Link Third Party Advisory VDB Entry
http://www.ubuntu.com/usn/USN-1712-1 Third Party Advisory
https://bugs.launchpad.net/inkscape/+bug/1025185 Exploit Issue Tracking
https://launchpad.net/inkscape/+milestone/0.48.4 Product
http://bazaar.launchpad.net/~inkscape.dev/inkscape/trunk/revision/11931 Patch
http://lists.fedoraproject.org/pipermail/package-announce/2012-December/095024.html Mailing List
http://lists.fedoraproject.org/pipermail/package-announce/2013-January/095380.html Mailing List
http://lists.fedoraproject.org/pipermail/package-announce/2013-January/095398.html Mailing List
http://lists.opensuse.org/opensuse-updates/2013-02/msg00041.html Mailing List
http://lists.opensuse.org/opensuse-updates/2013-02/msg00043.html Mailing List
http://www.openwall.com/lists/oss-security/2012/12/20/3 Exploit Mailing List
http://www.securityfocus.com/bid/56965 Broken Link Third Party Advisory VDB Entry
http://www.ubuntu.com/usn/USN-1712-1 Third Party Advisory
https://bugs.launchpad.net/inkscape/+bug/1025185 Exploit Issue Tracking
https://launchpad.net/inkscape/+milestone/0.48.4 Product
Configurations

Configuration 1 (hide)

cpe:2.3:a:inkscape:inkscape:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:fedoraproject:fedora:16:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:17:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:18:*:*:*:*:*:*:*

Configuration 3 (hide)

OR cpe:2.3:o:canonical:ubuntu_linux:10.04:*:*:*:-:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:11.10:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:-:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:12.10:*:*:*:*:*:*:*

Configuration 4 (hide)

OR cpe:2.3:o:opensuse:opensuse:11.4:*:*:*:*:*:*:*
cpe:2.3:o:opensuse:opensuse:12.1:*:*:*:*:*:*:*
cpe:2.3:o:opensuse:opensuse:12.2:*:*:*:*:*:*:*

History

21 Nov 2024, 01:45

Type Values Removed Values Added
References () http://bazaar.launchpad.net/~inkscape.dev/inkscape/trunk/revision/11931 - Patch () http://bazaar.launchpad.net/~inkscape.dev/inkscape/trunk/revision/11931 - Patch
References () http://lists.fedoraproject.org/pipermail/package-announce/2012-December/095024.html - Mailing List () http://lists.fedoraproject.org/pipermail/package-announce/2012-December/095024.html - Mailing List
References () http://lists.fedoraproject.org/pipermail/package-announce/2013-January/095380.html - Mailing List () http://lists.fedoraproject.org/pipermail/package-announce/2013-January/095380.html - Mailing List
References () http://lists.fedoraproject.org/pipermail/package-announce/2013-January/095398.html - Mailing List () http://lists.fedoraproject.org/pipermail/package-announce/2013-January/095398.html - Mailing List
References () http://lists.opensuse.org/opensuse-updates/2013-02/msg00041.html - Mailing List () http://lists.opensuse.org/opensuse-updates/2013-02/msg00041.html - Mailing List
References () http://lists.opensuse.org/opensuse-updates/2013-02/msg00043.html - Mailing List () http://lists.opensuse.org/opensuse-updates/2013-02/msg00043.html - Mailing List
References () http://www.openwall.com/lists/oss-security/2012/12/20/3 - Exploit, Mailing List () http://www.openwall.com/lists/oss-security/2012/12/20/3 - Exploit, Mailing List
References () http://www.securityfocus.com/bid/56965 - Broken Link, Third Party Advisory, VDB Entry () http://www.securityfocus.com/bid/56965 - Broken Link, Third Party Advisory, VDB Entry
References () http://www.ubuntu.com/usn/USN-1712-1 - Third Party Advisory () http://www.ubuntu.com/usn/USN-1712-1 - Third Party Advisory
References () https://bugs.launchpad.net/inkscape/+bug/1025185 - Exploit, Issue Tracking () https://bugs.launchpad.net/inkscape/+bug/1025185 - Exploit, Issue Tracking
References () https://launchpad.net/inkscape/+milestone/0.48.4 - Product () https://launchpad.net/inkscape/+milestone/0.48.4 - Product

15 Feb 2024, 20:18

Type Values Removed Values Added
CWE CWE-264 CWE-611
First Time Canonical
Canonical ubuntu Linux
Fedoraproject fedora
Opensuse opensuse
Fedoraproject
Opensuse
CVSS v2 : 2.1
v3 : unknown
v2 : 2.1
v3 : 5.5
References (FEDORA) http://lists.fedoraproject.org/pipermail/package-announce/2013-January/095380.html - (FEDORA) http://lists.fedoraproject.org/pipermail/package-announce/2013-January/095380.html - Mailing List
References (FEDORA) http://lists.fedoraproject.org/pipermail/package-announce/2012-December/095024.html - (FEDORA) http://lists.fedoraproject.org/pipermail/package-announce/2012-December/095024.html - Mailing List
References (FEDORA) http://lists.fedoraproject.org/pipermail/package-announce/2013-January/095398.html - (FEDORA) http://lists.fedoraproject.org/pipermail/package-announce/2013-January/095398.html - Mailing List
References (BID) http://www.securityfocus.com/bid/56965 - (BID) http://www.securityfocus.com/bid/56965 - Broken Link, Third Party Advisory, VDB Entry
References (SUSE) http://lists.opensuse.org/opensuse-updates/2013-02/msg00043.html - (SUSE) http://lists.opensuse.org/opensuse-updates/2013-02/msg00043.html - Mailing List
References (CONFIRM) http://bazaar.launchpad.net/~inkscape.dev/inkscape/trunk/revision/11931 - (CONFIRM) http://bazaar.launchpad.net/~inkscape.dev/inkscape/trunk/revision/11931 - Patch
References (SUSE) http://lists.opensuse.org/opensuse-updates/2013-02/msg00041.html - (SUSE) http://lists.opensuse.org/opensuse-updates/2013-02/msg00041.html - Mailing List
References (MLIST) http://www.openwall.com/lists/oss-security/2012/12/20/3 - Exploit (MLIST) http://www.openwall.com/lists/oss-security/2012/12/20/3 - Exploit, Mailing List
References (CONFIRM) https://bugs.launchpad.net/inkscape/+bug/1025185 - Exploit (CONFIRM) https://bugs.launchpad.net/inkscape/+bug/1025185 - Exploit, Issue Tracking
References (CONFIRM) https://launchpad.net/inkscape/+milestone/0.48.4 - (CONFIRM) https://launchpad.net/inkscape/+milestone/0.48.4 - Product
References (UBUNTU) http://www.ubuntu.com/usn/USN-1712-1 - (UBUNTU) http://www.ubuntu.com/usn/USN-1712-1 - Third Party Advisory
CPE cpe:2.3:a:inkscape:inkscape:0.48:*:*:*:*:*:*:*
cpe:2.3:a:inkscape:inkscape:0.48.2:*:*:*:*:*:*:*
cpe:2.3:a:inkscape:inkscape:0.45.1:*:*:*:*:*:*:*
cpe:2.3:a:inkscape:inkscape:0.48.1:*:*:*:*:*:*:*
cpe:2.3:a:inkscape:inkscape:0.40:*:*:*:*:*:*:*
cpe:2.3:a:inkscape:inkscape:0.44.1:*:*:*:*:*:*:*
cpe:2.3:a:inkscape:inkscape:0.42.2:*:*:*:*:*:*:*
cpe:2.3:a:inkscape:inkscape:0.46:*:*:*:*:*:*:*
cpe:2.3:a:inkscape:inkscape:0.37:*:*:*:*:*:*:*
cpe:2.3:a:inkscape:inkscape:0.47:pre1:*:*:*:*:*:*
cpe:2.3:a:inkscape:inkscape:0.48:pre1:*:*:*:*:*:*
cpe:2.3:a:inkscape:inkscape:0.47:pre3:*:*:*:*:*:*
cpe:2.3:a:inkscape:inkscape:0.48.3:*:*:*:*:*:*:*
cpe:2.3:a:inkscape:inkscape:0.41:*:*:*:*:*:*:*
cpe:2.3:a:inkscape:inkscape:0.47:pre4:*:*:*:*:*:*
cpe:2.3:a:inkscape:inkscape:0.38.1:*:*:*:*:*:*:*
cpe:2.3:a:inkscape:inkscape:0.44:*:*:*:*:*:*:*
cpe:2.3:a:inkscape:inkscape:0.39:*:*:*:*:*:*:*
cpe:2.3:a:inkscape:inkscape:0.42:*:*:*:*:*:*:*
cpe:2.3:a:inkscape:inkscape:0.47:pre2:*:*:*:*:*:*
cpe:2.3:a:inkscape:inkscape:0.47:pre0:*:*:*:*:*:*
cpe:2.3:a:inkscape:inkscape:0.48:pre0:*:*:*:*:*:*
cpe:2.3:a:inkscape:inkscape:0.47:*:*:*:*:*:*:*
cpe:2.3:a:inkscape:inkscape:0.43:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:10.04:*:*:*:-:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:11.10:*:*:*:*:*:*:*
cpe:2.3:o:opensuse:opensuse:11.4:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:18:*:*:*:*:*:*:*
cpe:2.3:o:opensuse:opensuse:12.1:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:17:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:16:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:-:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:12.10:*:*:*:*:*:*:*
cpe:2.3:o:opensuse:opensuse:12.2:*:*:*:*:*:*:*

Information

Published : 2013-01-18 11:48

Updated : 2024-11-21 01:45


NVD link : CVE-2012-5656

Mitre link : CVE-2012-5656

CVE.ORG link : CVE-2012-5656


JSON object : View

Products Affected

canonical

  • ubuntu_linux

opensuse

  • opensuse

fedoraproject

  • fedora

inkscape

  • inkscape
CWE
CWE-611

Improper Restriction of XML External Entity Reference