Vulnerability Name:

CVE-2012-5656 (CCN-80706)

Assigned:2012-12-17
Published:2012-12-17
Updated:2013-03-23
Summary:The rasterization process in Inkscape before 0.48.4 allows local users to read arbitrary files via an external entity in a SVG file, aka an XML external entity (XXE) injection attack.
CVSS v3 Severity:5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): None
Availibility (A): None
CVSS v2 Severity:2.1 Low (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N)
1.6 Low (Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
5.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
Vulnerability Type:CWE-264
Vulnerability Consequences:Obtain Information
References:Source: CONFIRM
Type: UNKNOWN
http://bazaar.launchpad.net/~inkscape.dev/inkscape/trunk/revision/11931

Source: MITRE
Type: CNA
CVE-2012-5656

Source: FEDORA
Type: UNKNOWN
FEDORA-2012-20643

Source: FEDORA
Type: UNKNOWN
FEDORA-2012-20620

Source: FEDORA
Type: UNKNOWN
FEDORA-2012-20621

Source: SUSE
Type: UNKNOWN
openSUSE-SU-2013:0294

Source: SUSE
Type: UNKNOWN
openSUSE-SU-2013:0297

Source: CCN
Type: Inkscape Web site
Inkscape

Source: CCN
Type: oss-security: Nicolas Gregoire | 17 Dec
CVE request: Inkscape fixes a XXE vulnerability during rasterization of SVG images

Source: MLIST
Type: Exploit
[oss-security] 20121219 Re: CVE request: Inkscape fixes a XXE vulnerability during rasterization of SVG images

Source: BID
Type: UNKNOWN
56965

Source: CCN
Type: BID-56965
Inkscape XML External Entity Information Disclosure Vulnerability

Source: UBUNTU
Type: UNKNOWN
USN-1712-1

Source: CONFIRM
Type: Exploit
https://bugs.launchpad.net/inkscape/+bug/1025185

Source: XF
Type: UNKNOWN
inkscape-xxe-injection(80706)

Source: CONFIRM
Type: UNKNOWN
https://launchpad.net/inkscape/+milestone/0.48.4

Vulnerable Configuration:Configuration 1:
  • cpe:/a:inkscape:inkscape:0.37:*:*:*:*:*:*:*
  • OR cpe:/a:inkscape:inkscape:0.38.1:*:*:*:*:*:*:*
  • OR cpe:/a:inkscape:inkscape:0.39:*:*:*:*:*:*:*
  • OR cpe:/a:inkscape:inkscape:0.40:*:*:*:*:*:*:*
  • OR cpe:/a:inkscape:inkscape:0.41:*:*:*:*:*:*:*
  • OR cpe:/a:inkscape:inkscape:0.42:*:*:*:*:*:*:*
  • OR cpe:/a:inkscape:inkscape:0.42.2:*:*:*:*:*:*:*
  • OR cpe:/a:inkscape:inkscape:0.43:*:*:*:*:*:*:*
  • OR cpe:/a:inkscape:inkscape:0.44:*:*:*:*:*:*:*
  • OR cpe:/a:inkscape:inkscape:0.44.1:*:*:*:*:*:*:*
  • OR cpe:/a:inkscape:inkscape:0.45.1:*:*:*:*:*:*:*
  • OR cpe:/a:inkscape:inkscape:0.46:*:*:*:*:*:*:*
  • OR cpe:/a:inkscape:inkscape:0.47:*:*:*:*:*:*:*
  • OR cpe:/a:inkscape:inkscape:0.47:pre0:*:*:*:*:*:*
  • OR cpe:/a:inkscape:inkscape:0.47:pre1:*:*:*:*:*:*
  • OR cpe:/a:inkscape:inkscape:0.47:pre2:*:*:*:*:*:*
  • OR cpe:/a:inkscape:inkscape:0.47:pre3:*:*:*:*:*:*
  • OR cpe:/a:inkscape:inkscape:0.47:pre4:*:*:*:*:*:*
  • OR cpe:/a:inkscape:inkscape:0.48:*:*:*:*:*:*:*
  • OR cpe:/a:inkscape:inkscape:0.48:pre0:*:*:*:*:*:*
  • OR cpe:/a:inkscape:inkscape:0.48:pre1:*:*:*:*:*:*
  • OR cpe:/a:inkscape:inkscape:0.48.1:*:*:*:*:*:*:*
  • OR cpe:/a:inkscape:inkscape:0.48.2:*:*:*:*:*:*:*
  • OR cpe:/a:inkscape:inkscape:0.48.3:*:*:*:*:*:*:*
  • OR cpe:/a:inkscape:inkscape:*:*:*:*:*:*:*:* (Version <= 0.48.3.1)

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:26186
    P
    Security update for libqt4 (Important)
    2021-12-22
    oval:org.opensuse.security:def:26176
    P
    Security update for speex (Moderate)
    2021-12-01
    oval:org.opensuse.security:def:26174
    P
    Security update for openexr (Moderate)
    2021-12-01
    oval:org.opensuse.security:def:26175
    P
    Security update for xen (Moderate)
    2021-12-01
    oval:org.opensuse.security:def:20125656
    V
    CVE-2012-5656
    2021-08-15
    oval:org.opensuse.security:def:36423
    P
    inkscape-0.46-62.43.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:55198
    P
    Security update for gstreamer-plugins-bad (Important)
    2021-06-07
    oval:org.opensuse.security:def:26048
    P
    Security update for the Linux Kernel (Important)
    2021-05-13
    oval:org.opensuse.security:def:55876
    P
    Security update for the Linux Kernel (Live Patch 37 for SLE 12 SP2) (Important)
    2021-04-12
    oval:org.opensuse.security:def:57152
    P
    Security update for the Linux Kernel (Live Patch 34 for SLE 12 SP3) (Important)
    2021-02-10
    oval:org.opensuse.security:def:54753
    P
    Security update for the Linux Kernel (Live Patch 35 for SLE 12 SP2) (Important)
    2021-02-10
    oval:org.opensuse.security:def:25984
    P
    Security update for cyrus-sasl (Important)
    2020-12-28
    oval:org.opensuse.security:def:25973
    P
    Security update for the Linux Kernel (Important)
    2020-12-09
    oval:org.opensuse.security:def:25972
    P
    Security update for postgresql12 (Important)
    2020-12-04
    oval:org.opensuse.security:def:26704
    P
    g3utils on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26853
    P
    NetworkManager on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27113
    P
    ecryptfs-utils-32bit on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27691
    P
    Security update for xorg-x11-libXt
    2020-12-01
    oval:org.opensuse.security:def:55032
    P
    wdiff on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26257
    P
    Security update for icu (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26748
    P
    libgnomesu on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26250
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:26892
    P
    expat on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27114
    P
    ed on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27744
    P
    Security update for MozillaFirefox
    2020-12-01
    oval:org.opensuse.security:def:57226
    P
    Security update for inkscape
    2020-12-01
    oval:org.opensuse.security:def:26314
    P
    Security update for iperf (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27386
    P
    cyrus-imapd-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26378
    P
    Security update for chromium (Important)
    2020-12-01
    oval:org.opensuse.security:def:26906
    P
    gmime on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27125
    P
    foomatic-filters on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27793
    P
    Security update for libgcrypt (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:54352
    P
    perl-Config-IniFiles on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:55483
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:26398
    P
    Security update for pdns-recursor (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27421
    P
    inkscape on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26459
    P
    Security update for chromium (Important)
    2020-12-01
    oval:org.opensuse.security:def:26950
    P
    libgdiplus0 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27189
    P
    libgtop on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27832
    P
    Security update for lxc (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:54353
    P
    perl-HTML-Parser on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:55591
    P
    Security update for kernel-source (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26549
    P
    ft2demos on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26516
    P
    NetworkManager on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27588
    P
    xorg-x11-libXv-devel-32bit on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27317
    P
    vte on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27846
    P
    Security update for openldap2
    2020-12-01
    oval:org.opensuse.security:def:54375
    P
    rsync on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:55683
    P
    Security update for libpng12 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26602
    P
    libsndfile on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26600
    P
    librpcsecgss on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27623
    P
    Security update for inkscape
    2020-12-01
    oval:org.opensuse.security:def:27399
    P
    fileshareset on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27890
    P
    Security update for samba (Important)
    2020-12-01
    oval:org.opensuse.security:def:54515
    P
    libX11-6 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:55757
    P
    Security update for ldb, samba, talloc, tdb, tevent (Important)
    2020-12-01
    oval:org.opensuse.security:def:26651
    P
    xen on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26751
    P
    libltdl7 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27456
    P
    libksba-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28528
    P
    Security update for ImageMagick
    2020-12-01
    oval:org.opensuse.security:def:55795
    P
    Security update for perl (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26690
    P
    emacs on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26804
    P
    perl-HTML-Parser on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27540
    P
    ppp-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28563
    P
    Security update for inkscape
    2020-12-01
    oval:org.opensuse.security:def:54926
    P
    libsndfile1 on GA media (Moderate)
    2020-12-01
    oval:org.mitre.oval:def:25552
    P
    SUSE-SU-2013:0351-1 -- Security update for inkscape
    2014-09-08
    oval:org.mitre.oval:def:25765
    P
    SUSE-SU-2013:0350-1 -- Security update for inkscape
    2014-09-08
    oval:org.mitre.oval:def:17748
    P
    USN-1712-1 -- inkscape vulnerabilities
    2014-07-21
    oval:org.opensuse.security:def:79860
    P
    Security update for inkscape
    2013-02-20
    oval:com.ubuntu.precise:def:20125656000
    V
    CVE-2012-5656 on Ubuntu 12.04 LTS (precise) - medium.
    2013-01-18
    BACK
    inkscape inkscape 0.37
    inkscape inkscape 0.38.1
    inkscape inkscape 0.39
    inkscape inkscape 0.40
    inkscape inkscape 0.41
    inkscape inkscape 0.42
    inkscape inkscape 0.42.2
    inkscape inkscape 0.43
    inkscape inkscape 0.44
    inkscape inkscape 0.44.1
    inkscape inkscape 0.45.1
    inkscape inkscape 0.46
    inkscape inkscape 0.47
    inkscape inkscape 0.47 pre0
    inkscape inkscape 0.47 pre1
    inkscape inkscape 0.47 pre2
    inkscape inkscape 0.47 pre3
    inkscape inkscape 0.47 pre4
    inkscape inkscape 0.48
    inkscape inkscape 0.48 pre0
    inkscape inkscape 0.48 pre1
    inkscape inkscape 0.48.1
    inkscape inkscape 0.48.2
    inkscape inkscape 0.48.3
    inkscape inkscape *