4.3
CVSSv2

CVE-2013-1881

Published: 10/10/2013 Updated: 08/12/2016
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

GNOME libsvg prior to 2.39.0 allows remote malicious users to read arbitrary files via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

gnome librsvg 2.35.1

gnome librsvg 2.35.0

gnome librsvg 2.3.1

gnome librsvg 2.3.0

gnome librsvg 2.36.2

gnome librsvg 2.36.1

gnome librsvg 2.34.0

gnome librsvg 2.32.1

gnome librsvg 2.26.1

gnome librsvg 2.26.0

gnome librsvg 2.2.3

gnome librsvg 2.2.2

gnome librsvg 2.16.0

gnome librsvg 2.15.90

gnome librsvg 2.13.93

gnome librsvg 2.13.92

gnome librsvg 2.13.0

gnome librsvg 2.12.7

gnome librsvg 2.12.0

gnome librsvg 2.11.1

gnome librsvg 2.1.0

gnome librsvg 2.0.1

gnome librsvg 2.0.0

gnome librsvg 1.0.3

gnome librsvg 1.0.2

gnome librsvg 2.22.1

gnome librsvg 2.22.0

gnome librsvg 2.20.0

gnome librsvg 2.18.2

gnome librsvg 2.18.1

gnome librsvg 2.14.3

gnome librsvg 2.14.2

gnome librsvg 2.13.4

gnome librsvg 2.13.3

gnome librsvg 2.12.4

gnome librsvg 2.12.3

gnome librsvg 2.1.4

gnome librsvg 2.1.3

gnome librsvg 1.1.4

gnome librsvg 1.1.3

gnome librsvg

gnome librsvg 2.36.0

gnome librsvg 2.35.2

gnome librsvg 2.32.0

gnome librsvg 2.31.0

gnome librsvg 2.22.3

gnome librsvg 2.22.2

gnome librsvg 2.2.1

gnome librsvg 2.2.0

gnome librsvg 2.15.0

gnome librsvg 2.14.4

gnome librsvg 2.13.91

gnome librsvg 2.13.90

gnome librsvg 2.13.5

gnome librsvg 2.12.6

gnome librsvg 2.12.5

gnome librsvg 2.11.0

gnome librsvg 2.1.5

gnome librsvg 1.1.6

gnome librsvg 1.1.5

gnome librsvg 1.0.1

gnome librsvg 1.0.0

gnome librsvg 2.36.3

gnome librsvg 2.34.2

gnome librsvg 2.34.1

gnome librsvg 2.26.3

gnome librsvg 2.26.2

gnome librsvg 2.2.5

gnome librsvg 2.2.4

gnome librsvg 2.18.0

gnome librsvg 2.16.1

gnome librsvg 2.14.1

gnome librsvg 2.14.0

gnome librsvg 2.13.2

gnome librsvg 2.13.1

gnome librsvg 2.12.2

gnome librsvg 2.12.1

gnome librsvg 2.1.2

gnome librsvg 2.1.1

gnome librsvg 1.1.2

gnome librsvg 1.1.1

Vendor Advisories

Synopsis Moderate: librsvg2 security update Type/Severity Security Advisory: Moderate Topic Updated librsvg2 packages that fix one security issue are now available forRed Hat Enterprise Linux 6The Red Hat Security Response Team has rated this update as having moderatesecurity impact A Common Vulnerability ...
Debian Bug report logs - #724741 librsvg: CVE-2013-1881 Package: librsvg; Maintainer for librsvg is Debian GNOME Maintainers <pkg-gnome-maintainers@listsaliothdebianorg>; Reported by: Moritz Muehlenhoff <jmm@inutilorg> Date: Fri, 27 Sep 2013 11:57:01 UTC Severity: important Tags: patch, security Found in version ...
Librsvg could be made to expose sensitive information ...
This update provides a compatibility fix for GTK+ ...
GNOME libsvg before 2390 allows remote attackers to read arbitrary files via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue ...