CVE Vulnerabilities

CVE-2015-0250

Published: Mar 24, 2015 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.4 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:P
RedHat/V2
5.8 MODERATE
AV:N/AC:M/Au:N/C:P/I:N/A:P
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

XML external entity (XXE) vulnerability in the SVG to (1) PNG and (2) JPG conversion classes in Apache Batik 1.x before 1.8 allows remote attackers to read arbitrary files or cause a denial of service via a crafted SVG file.

Affected Software

NameVendorStart VersionEnd Version
Ubuntu_linuxCanonical12.04 (including)12.04 (including)
Ubuntu_linuxCanonical14.04 (including)14.04 (including)
Ubuntu_linuxCanonical14.10 (including)14.10 (including)
Red Hat JBoss BPMS 6.1RedHatbatik*
Red Hat JBoss BPMS 6.2RedHatbatik*
Red Hat JBoss BRMS 6.1RedHatbatik*
Red Hat JBoss BRMS 6.2RedHatbatik*
BatikUbuntudevel*
BatikUbuntulucid*
BatikUbuntuprecise*
BatikUbuntutrusty*
BatikUbuntuupstream*
BatikUbuntuutopic*

References