CVE-2012-5656: XEE
Published Jan 18, 2013
·Updated
The rasterization process in Inkscape before 0.48.4 allows local users to read arbitrary files via an external entity in a SVG file, aka an XML external entity (XXE) injection attack.
Affected Software
36 affected components
Inkscape Inkscape<=0.48.3.1
Inkscape Inkscape=0.37
Inkscape Inkscape=0.38.1
Inkscape Inkscape=0.39
Inkscape Inkscape=0.40
Inkscape Inkscape=0.41
Inkscape Inkscape=0.42
Inkscape Inkscape=0.42.2
Inkscape Inkscape=0.43
Inkscape Inkscape=0.44
Inkscape Inkscape=0.44.1
Inkscape Inkscape=0.45.1
Inkscape Inkscape=0.46
Inkscape Inkscape=0.47
Inkscape Inkscape=0.47-pre0
Inkscape Inkscape=0.47-pre1
Inkscape Inkscape=0.47-pre2
Inkscape Inkscape=0.47-pre3
Inkscape Inkscape=0.47-pre4
Inkscape Inkscape=0.48
Inkscape Inkscape=0.48-pre0
Inkscape Inkscape=0.48-pre1
Inkscape Inkscape=0.48.1
Inkscape Inkscape=0.48.2
Inkscape Inkscape=0.48.3
Inkscape Inkscape<0.48.4
Fedoraproject Fedora=16
Fedoraproject Fedora=17
Fedoraproject Fedora=18
Canonical Ubuntu Linux=10.04
Canonical Ubuntu Linux=11.10
Canonical Ubuntu Linux=12.04
Canonical Ubuntu Linux=12.10
openSUSE openSUSE=11.4
openSUSE openSUSE=12.1
openSUSE openSUSE=12.2
Remediation
Event History
Jan 18, 2013
CVE Published
via MITRE·11:00 AM
Data Sourced
via MITRE·11:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-5656?
CVE-2012-5656 is categorized as a medium severity vulnerability due to its potential for local file disclosure.
2
How do I fix CVE-2012-5656?
To fix CVE-2012-5656, update Inkscape to version 0.48.4 or later, which mitigates the XML external entity injection vulnerability.
3
Who is affected by CVE-2012-5656?
Users of Inkscape versions prior to 0.48.4, including multiple versions, are affected by CVE-2012-5656.
4
What type of vulnerability is CVE-2012-5656?
CVE-2012-5656 is an XML External Entity (XXE) injection vulnerability allowing local file read access.
5
Can CVE-2012-5656 be exploited remotely?
CVE-2012-5656 requires local user access to exploit, making it less of a threat for remote attacks.