CVE-2005-0508: Medium severity Apache Batik vulnerability
Published Feb 22, 2005
·Updated
Unknown vulnerability in Squiggle for Batik before 1.5.1 allows attackers to bypass certain access controls via certain features of the Rhino scripting engine due to a "script security issue."
Affected Software
8 affected components
Apache Batik=1.5
Apache Batik=1.0
Apache Batik=1.1
Apache Batik=1.1.1
Apache Batik=1.0
Apache Batik=1.1
Apache Batik=1.1.1
Apache Batik=1.5
Remediation
Patch Available
Patch Available
Event History
Feb 22, 2005
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-0508?
CVE-2005-0508 has a medium severity rating due to its potential to allow access control bypass in vulnerable versions of Apache Batik.
2
How do I fix CVE-2005-0508?
To mitigate CVE-2005-0508, upgrade to a version of Apache Batik later than 1.5.1.
3
Which versions of Apache Batik are affected by CVE-2005-0508?
CVE-2005-0508 affects Apache Batik versions 1.0, 1.1, and 1.5, prior to 1.5.1.
4
What type of vulnerability is CVE-2005-0508?
CVE-2005-0508 is categorized as a script security issue that allows for bypassing certain access controls.
5
Who can exploit CVE-2005-0508?
Attackers with knowledge of specific features of the Rhino scripting engine can exploit CVE-2005-0508.