First published: Fri Jan 18 2013(Updated: )
The rasterization process in Inkscape before 0.48.4 allows local users to read arbitrary files via an external entity in a SVG file, aka an XML external entity (XXE) injection attack.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Inkscape | <=0.48.3.1 | |
Inkscape | =0.37 | |
Inkscape | =0.38.1 | |
Inkscape | =0.39 | |
Inkscape | =0.40 | |
Inkscape | =0.41 | |
Inkscape | =0.42 | |
Inkscape | =0.42.2 | |
Inkscape | =0.43 | |
Inkscape | =0.44 | |
Inkscape | =0.44.1 | |
Inkscape | =0.45.1 | |
Inkscape | =0.46 | |
Inkscape | =0.47 | |
Inkscape | =0.47-pre0 | |
Inkscape | =0.47-pre1 | |
Inkscape | =0.47-pre2 | |
Inkscape | =0.47-pre3 | |
Inkscape | =0.47-pre4 | |
Inkscape | =0.48 | |
Inkscape | =0.48-pre0 | |
Inkscape | =0.48-pre1 | |
Inkscape | =0.48.1 | |
Inkscape | =0.48.2 | |
Inkscape | =0.48.3 | |
Inkscape | <0.48.4 | |
Fedora | =16 | |
Fedora | =17 | |
Fedora | =18 | |
Ubuntu Linux | =10.04 | |
Ubuntu Linux | =11.10 | |
Ubuntu Linux | =12.04 | |
Ubuntu Linux | =12.10 | |
openSUSE libeconf | =11.4 | |
openSUSE libeconf | =12.1 | |
openSUSE libeconf | =12.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-5656 is categorized as a medium severity vulnerability due to its potential for local file disclosure.
To fix CVE-2012-5656, update Inkscape to version 0.48.4 or later, which mitigates the XML external entity injection vulnerability.
Users of Inkscape versions prior to 0.48.4, including multiple versions, are affected by CVE-2012-5656.
CVE-2012-5656 is an XML External Entity (XXE) injection vulnerability allowing local file read access.
CVE-2012-5656 requires local user access to exploit, making it less of a threat for remote attacks.