Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Date: Wed, 19 Dec 2012 22:43:53 -0700
From: Kurt Seifried <>
CC: Jan Lieskovsky <>,
        Nicolas Grégoire <>,
        "Steven M. Christey" <>
Subject: Re: CVE request: Inkscape fixes a XXE vulnerability
 during rasterization of SVG images

Hash: SHA1

On 12/19/2012 03:37 AM, Jan Lieskovsky wrote:
> Hi Kurt, Nicolas, vendors,
> ----- Original Message ----- -----BEGIN PGP SIGNED MESSAGE----- 
> Hash: SHA1
> On 12/18/2012 08:44 PM, Kurt Seifried wrote:
>> On 12/17/2012 01:27 PM, Nicolas Grégoire wrote:
>>> Inkscape is vulnerable to XXE attacks during 
>>> rasterization/export of SVG images: 
>>> Impact: The impact of this vulnerability range form denial of 
>>> service to file disclosure. Under Windows, it can also be used 
>>> to steal LM/NTLM hashes.
>>> PoC: During rasterization, entities declared in the DTD are 
>>> dereferenced and the content of the target file is included in 
>>> the output. Command-line used: "inkscape -e xxe-inkscape.png 
>>> xxe.svg" (PoC files are attached to the ticket)
>>> References: CWE-827: Improper Control of Document Type
>>> Definition
>>> Regards, Nicolas Grégoire
>> This already has a CVE reference in the page:
>> CVE References
>> 2012-1102
>> To clarify that CVE was assigned to 
>> so this is probably an error, someone needs to tidy that bug up
>> and post links to the source/etc so I can see whats going on.
> That's correct. CVE-2012-1102 has been assigned to the perl
> XML-Atom issue.
> Assuming the source of the slight confusion is this comment: 
> and the CVE id in the references.
> But from the context of that bug, comment c#13 was used just to
> reference patch for same issue in perl XML-Atom (CVE-2012-1102) 
> issue, when searching a patch for inkscape.
> Which later resulted into upstream inkscape commit: 
>  referenced in (subsequent) comment c#14: 
> So CVE-2012-1102 identifier is for perl XML-Atom problem. And this 
> (same XXE problem) being present in inkscape should get a new CVE
> id yet.
> Thank you && Regards, Jan. -- Jan iankko Lieskovsky / Red Hat
> Security Response Team

Please use CVE-2012-5656 for the Inkscape fixes a XXE vulnerability
during rasterization of SVG images

- -- 
Kurt Seifried Red Hat Security Response Team (SRT)
PGP: 0x5E267993 A90B F995 7350 148F 66BF 7554 160D 4553 5E26 7993

Version: GnuPG v1.4.12 (GNU/Linux)


Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.