CVE Vulnerabilities

CVE-2015-0250

Published: Mar 24, 2015 | Modified: Nov 21, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.4 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:P
RedHat/V2
5.8 MODERATE
AV:N/AC:M/Au:N/C:P/I:N/A:P
RedHat/V3
Ubuntu
MEDIUM

XML external entity (XXE) vulnerability in the SVG to (1) PNG and (2) JPG conversion classes in Apache Batik 1.x before 1.8 allows remote attackers to read arbitrary files or cause a denial of service via a crafted SVG file.

Affected Software

Name Vendor Start Version End Version
Ubuntu_linux Canonical 12.04 (including) 12.04 (including)
Ubuntu_linux Canonical 14.04 (including) 14.04 (including)
Ubuntu_linux Canonical 14.10 (including) 14.10 (including)
Red Hat JBoss BPMS 6.1 RedHat batik *
Red Hat JBoss BPMS 6.2 RedHat batik *
Red Hat JBoss BRMS 6.1 RedHat batik *
Red Hat JBoss BRMS 6.2 RedHat batik *
Batik Ubuntu devel *
Batik Ubuntu lucid *
Batik Ubuntu precise *
Batik Ubuntu trusty *
Batik Ubuntu upstream *
Batik Ubuntu utopic *

References