CVE-2012-6076: Medium severity inkscape vulnerability
Published Mar 12, 2013
·Updated
Inkscape before 0.48.4 reads .eps files from /tmp instead of the current directory, which might cause Inkspace to process unintended files, allow local users to obtain sensitive information, and possibly have other unspecified impacts.
Affected Software
25 affected components
Inkscape Inkscape<=0.48.3.1
Inkscape Inkscape=0.37
Inkscape Inkscape=0.38.1
Inkscape Inkscape=0.39
Inkscape Inkscape=0.40
Inkscape Inkscape=0.41
Inkscape Inkscape=0.42
Inkscape Inkscape=0.42.2
Inkscape Inkscape=0.43
Inkscape Inkscape=0.44
Inkscape Inkscape=0.44.1
Inkscape Inkscape=0.45.1
Inkscape Inkscape=0.46
Inkscape Inkscape=0.47
Inkscape Inkscape=0.47-pre0
Inkscape Inkscape=0.47-pre1
Inkscape Inkscape=0.47-pre2
Inkscape Inkscape=0.47-pre3
Inkscape Inkscape=0.47-pre4
Inkscape Inkscape=0.48
Inkscape Inkscape=0.48-pre0
Inkscape Inkscape=0.48-pre1
Inkscape Inkscape=0.48.1
Inkscape Inkscape=0.48.2
Inkscape Inkscape=0.48.3
Event History
Mar 12, 2013
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-6076?
CVE-2012-6076 has been classified as a moderate severity vulnerability due to its potential impact on sensitive information.
2
How do I fix CVE-2012-6076?
To fix CVE-2012-6076, update Inkscape to version 0.48.4 or later.
3
What types of files are affected by CVE-2012-6076?
CVE-2012-6076 affects .eps files that are read from the /tmp directory instead of the current directory.
4
Can CVE-2012-6076 lead to sensitive data exposure?
Yes, CVE-2012-6076 can allow local users to obtain sensitive information by processing unintended files.
5
Is CVE-2012-6076 present in Inkscape versions after 0.48.3.1?
CVE-2012-6076 is present in Inkscape versions prior to 0.48.4.