CVE-2013-1881

Description

GNOME libsvg before 2.39.0 allows remote attackers to read arbitrary files via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

Risk Information

Base Score
7.5
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Score
Exploitation Probability
7.767

Associated Vulnerability

VulnerabilityOS Platform
renderer library for SVG files (USN-2149-1) librsvg2-2_2.36.1-0ubuntu1.1_i386.debLinux
renderer library for SVG files (USN-2149-1) librsvg2-2_2.36.1-0ubuntu1.1_amd64.debLinux
GTK+ graphical user interface library (USN-2149-2) libgtk-3-0_3.4.2-0ubuntu0.7_i386.debLinux
GTK+ graphical user interface library (USN-2149-2) libgtk-3-0_3.4.2-0ubuntu0.7_amd64.debLinux
(RHSA-2014:0127) Moderate: librsvg2 security update librsvg2-2.26.0-6.el6_5.3.i686.rpmLinux
(RHSA-2014:0127) Moderate: librsvg2 security update librsvg2-devel-2.26.0-6.el6_5.3.i686.rpmLinux
SUSE-SU-2015:1785-1(SUSE Linux Enterprise Desktop 11-SP3 ) librsvg-2.26.0-2.5.1.x86_64.rpmLinux
SUSE-SU-2015:1785-1(SUSE Linux Enterprise Desktop 11-SP3 ) librsvg-32bit-2.26.0-2.5.1.x86_64.rpmLinux
SUSE-SU-2015:1785-1(SUSE Linux Enterprise Desktop 11-SP3 ) rsvg-view-2.26.0-2.5.1.x86_64.rpmLinux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234