Vulnerability Name:

CVE-2012-6076 (CCN-82833)

Assigned:2012-12-29
Published:2012-12-29
Updated:2013-03-18
Summary:Inkscape before 0.48.4 reads .eps files from /tmp instead of the current directory, which might cause Inkspace to process unintended files, allow local users to obtain sensitive information, and possibly have other unspecified impacts.
CVSS v3 Severity:4.0 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): None
Availibility (A): None
CVSS v2 Severity:4.4 Medium (CVSS v2 Vector: AV:L/AC:M/Au:N/C:P/I:P/A:P)
3.2 Low (Temporal CVSS v2 Vector: AV:L/AC:M/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
2.1 Low (CCN CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N)
1.6 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
Vulnerability Type:CWE-264
Vulnerability Consequences:Obtain Information
References:Source: MISC
Type: UNKNOWN
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=654341

Source: MITRE
Type: CNA
CVE-2012-6076

Source: CCN
Type: Inkscape Web site
Inkscape

Source: SUSE
Type: UNKNOWN
openSUSE-SU-2013:0294

Source: SUSE
Type: UNKNOWN
openSUSE-SU-2013:0297

Source: CCN
Type: oss-sec mailing list, Sat, 29 Dec 2012 20:28:08 -0700
Re: Inkscape reads .eps files from /tmp instead of the current directory

Source: MLIST
Type: UNKNOWN
[oss-security] 20121229 Re: Inkscape reads .eps files from /tmp instead of the current directory

Source: CCN
Type: BID-57636
Inkscape '.eps' File Local Security Vulnerability

Source: UBUNTU
Type: UNKNOWN
USN-1712-1

Source: CONFIRM
Type: UNKNOWN
https://bugs.launchpad.net/inkscape/+bug/911146

Source: XF
Type: UNKNOWN
inkscape-eps-information-disclosure(82833)

Vulnerable Configuration:Configuration 1:
  • cpe:/a:inkscape:inkscape:0.37:*:*:*:*:*:*:*
  • OR cpe:/a:inkscape:inkscape:0.38.1:*:*:*:*:*:*:*
  • OR cpe:/a:inkscape:inkscape:0.39:*:*:*:*:*:*:*
  • OR cpe:/a:inkscape:inkscape:0.40:*:*:*:*:*:*:*
  • OR cpe:/a:inkscape:inkscape:0.41:*:*:*:*:*:*:*
  • OR cpe:/a:inkscape:inkscape:0.42:*:*:*:*:*:*:*
  • OR cpe:/a:inkscape:inkscape:0.42.2:*:*:*:*:*:*:*
  • OR cpe:/a:inkscape:inkscape:0.43:*:*:*:*:*:*:*
  • OR cpe:/a:inkscape:inkscape:0.44:*:*:*:*:*:*:*
  • OR cpe:/a:inkscape:inkscape:0.44.1:*:*:*:*:*:*:*
  • OR cpe:/a:inkscape:inkscape:0.45.1:*:*:*:*:*:*:*
  • OR cpe:/a:inkscape:inkscape:0.46:*:*:*:*:*:*:*
  • OR cpe:/a:inkscape:inkscape:0.47:*:*:*:*:*:*:*
  • OR cpe:/a:inkscape:inkscape:0.47:pre0:*:*:*:*:*:*
  • OR cpe:/a:inkscape:inkscape:0.47:pre1:*:*:*:*:*:*
  • OR cpe:/a:inkscape:inkscape:0.47:pre2:*:*:*:*:*:*
  • OR cpe:/a:inkscape:inkscape:0.47:pre3:*:*:*:*:*:*
  • OR cpe:/a:inkscape:inkscape:0.47:pre4:*:*:*:*:*:*
  • OR cpe:/a:inkscape:inkscape:0.48:*:*:*:*:*:*:*
  • OR cpe:/a:inkscape:inkscape:0.48:pre0:*:*:*:*:*:*
  • OR cpe:/a:inkscape:inkscape:0.48:pre1:*:*:*:*:*:*
  • OR cpe:/a:inkscape:inkscape:0.48.1:*:*:*:*:*:*:*
  • OR cpe:/a:inkscape:inkscape:0.48.2:*:*:*:*:*:*:*
  • OR cpe:/a:inkscape:inkscape:0.48.3:*:*:*:*:*:*:*
  • OR cpe:/a:inkscape:inkscape:*:*:*:*:*:*:*:* (Version <= 0.48.3.1)

  • Configuration CCN 1:
  • cpe:/a:inkscape:inkscape:0.48.3:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:26186
    P
    Security update for libqt4 (Important)
    2021-12-22
    oval:org.opensuse.security:def:26174
    P
    Security update for openexr (Moderate)
    2021-12-01
    oval:org.opensuse.security:def:26175
    P
    Security update for xen (Moderate)
    2021-12-01
    oval:org.opensuse.security:def:26176
    P
    Security update for speex (Moderate)
    2021-12-01
    oval:org.opensuse.security:def:20126076
    V
    CVE-2012-6076
    2021-08-15
    oval:org.opensuse.security:def:36423
    P
    inkscape-0.46-62.43.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:55198
    P
    Security update for gstreamer-plugins-bad (Important)
    2021-06-07
    oval:org.opensuse.security:def:26048
    P
    Security update for the Linux Kernel (Important)
    2021-05-13
    oval:org.opensuse.security:def:55876
    P
    Security update for the Linux Kernel (Live Patch 37 for SLE 12 SP2) (Important)
    2021-04-12
    oval:org.opensuse.security:def:54753
    P
    Security update for the Linux Kernel (Live Patch 35 for SLE 12 SP2) (Important)
    2021-02-10
    oval:org.opensuse.security:def:57152
    P
    Security update for the Linux Kernel (Live Patch 34 for SLE 12 SP3) (Important)
    2021-02-10
    oval:org.opensuse.security:def:25984
    P
    Security update for cyrus-sasl (Important)
    2020-12-28
    oval:org.opensuse.security:def:25973
    P
    Security update for the Linux Kernel (Important)
    2020-12-09
    oval:org.opensuse.security:def:25972
    P
    Security update for postgresql12 (Important)
    2020-12-04
    oval:org.opensuse.security:def:26378
    P
    Security update for chromium (Important)
    2020-12-01
    oval:org.opensuse.security:def:26906
    P
    gmime on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27125
    P
    foomatic-filters on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27793
    P
    Security update for libgcrypt (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:54352
    P
    perl-Config-IniFiles on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:55483
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:26398
    P
    Security update for pdns-recursor (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27421
    P
    inkscape on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26459
    P
    Security update for chromium (Important)
    2020-12-01
    oval:org.opensuse.security:def:26950
    P
    libgdiplus0 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27189
    P
    libgtop on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27832
    P
    Security update for lxc (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:54353
    P
    perl-HTML-Parser on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:55591
    P
    Security update for kernel-source (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26549
    P
    ft2demos on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26516
    P
    NetworkManager on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27588
    P
    xorg-x11-libXv-devel-32bit on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27317
    P
    vte on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27846
    P
    Security update for openldap2
    2020-12-01
    oval:org.opensuse.security:def:54375
    P
    rsync on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:55683
    P
    Security update for libpng12 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26602
    P
    libsndfile on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26600
    P
    librpcsecgss on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27623
    P
    Security update for inkscape
    2020-12-01
    oval:org.opensuse.security:def:27399
    P
    fileshareset on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27890
    P
    Security update for samba (Important)
    2020-12-01
    oval:org.opensuse.security:def:54515
    P
    libX11-6 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:55757
    P
    Security update for ldb, samba, talloc, tdb, tevent (Important)
    2020-12-01
    oval:org.opensuse.security:def:26651
    P
    xen on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26751
    P
    libltdl7 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27456
    P
    libksba-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28528
    P
    Security update for ImageMagick
    2020-12-01
    oval:org.opensuse.security:def:55795
    P
    Security update for perl (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26690
    P
    emacs on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26804
    P
    perl-HTML-Parser on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27540
    P
    ppp-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28563
    P
    Security update for inkscape
    2020-12-01
    oval:org.opensuse.security:def:54926
    P
    libsndfile1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26704
    P
    g3utils on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26853
    P
    NetworkManager on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27113
    P
    ecryptfs-utils-32bit on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27691
    P
    Security update for xorg-x11-libXt
    2020-12-01
    oval:org.opensuse.security:def:55032
    P
    wdiff on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26257
    P
    Security update for icu (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26748
    P
    libgnomesu on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26250
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:26892
    P
    expat on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27114
    P
    ed on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27744
    P
    Security update for MozillaFirefox
    2020-12-01
    oval:org.opensuse.security:def:57226
    P
    Security update for inkscape
    2020-12-01
    oval:org.opensuse.security:def:26314
    P
    Security update for iperf (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27386
    P
    cyrus-imapd-devel on GA media (Moderate)
    2020-12-01
    oval:org.mitre.oval:def:25552
    P
    SUSE-SU-2013:0351-1 -- Security update for inkscape
    2014-09-08
    oval:org.mitre.oval:def:17748
    P
    USN-1712-1 -- inkscape vulnerabilities
    2014-07-21
    oval:com.ubuntu.precise:def:20126076000
    V
    CVE-2012-6076 on Ubuntu 12.04 LTS (precise) - low.
    2013-03-12
    oval:org.opensuse.security:def:79860
    P
    Security update for inkscape
    2013-02-20
    BACK
    inkscape inkscape 0.37
    inkscape inkscape 0.38.1
    inkscape inkscape 0.39
    inkscape inkscape 0.40
    inkscape inkscape 0.41
    inkscape inkscape 0.42
    inkscape inkscape 0.42.2
    inkscape inkscape 0.43
    inkscape inkscape 0.44
    inkscape inkscape 0.44.1
    inkscape inkscape 0.45.1
    inkscape inkscape 0.46
    inkscape inkscape 0.47
    inkscape inkscape 0.47 pre0
    inkscape inkscape 0.47 pre1
    inkscape inkscape 0.47 pre2
    inkscape inkscape 0.47 pre3
    inkscape inkscape 0.47 pre4
    inkscape inkscape 0.48
    inkscape inkscape 0.48 pre0
    inkscape inkscape 0.48 pre1
    inkscape inkscape 0.48.1
    inkscape inkscape 0.48.2
    inkscape inkscape 0.48.3
    inkscape inkscape *
    inkscape inkscape 0.48.3