Description
XML external entity (XXE) vulnerability in the SVG to (1) PNG and (2) JPG conversion classes in Apache Batik 1.x before 1.8 allows remote attackers to read arbitrary files or cause a denial of service via a crafted SVG file.
Remediation
References
http://seclists.org/fulldisclosure/2015/Mar/142
http://xmlgraphics.apache.org/security.html
http://www.ubuntu.com/usn/USN-2548-1
http://packetstormsecurity.com/files/130964/Apache-Batik-XXE-Injection.html
http://www.mandriva.com/security/advisories?name=MDVSA-2015:203
http://advisories.mageia.org/MGASA-2015-0138.html
http://rhn.redhat.com/errata/RHSA-2016-0041.html
http://rhn.redhat.com/errata/RHSA-2016-0042.html
http://www-01.ibm.com/support/docview.wss?uid=swg21963275
http://www.securitytracker.com/id/1032781
http://www.debian.org/security/2015/dsa-3205
Related Vulnerabilities
CVE-2016-3088 Vulnerability in maven package org.apache.activemq:activemq-fileserver
CVE-2023-38286 Vulnerability in maven package org.thymeleaf:thymeleaf
CVE-2018-1000614 Vulnerability in maven package org.onosproject:onos-netconf-provider-alarm
CVE-2018-3738 Vulnerability in npm package protobufjs
CVE-2023-22899 Vulnerability in maven package net.lingala.zip4j:zip4j