Description
XML external entity (XXE) vulnerability in the SVG to (1) PNG and (2) JPG conversion classes in Apache Batik 1.x before 1.8 allows remote attackers to read arbitrary files or cause a denial of service via a crafted SVG file.
Remediation
References
http://seclists.org/fulldisclosure/2015/Mar/142
http://xmlgraphics.apache.org/security.html
http://www.ubuntu.com/usn/USN-2548-1
http://packetstormsecurity.com/files/130964/Apache-Batik-XXE-Injection.html
http://www.mandriva.com/security/advisories?name=MDVSA-2015:203
http://advisories.mageia.org/MGASA-2015-0138.html
http://rhn.redhat.com/errata/RHSA-2016-0041.html
http://rhn.redhat.com/errata/RHSA-2016-0042.html
http://www-01.ibm.com/support/docview.wss?uid=swg21963275
http://www.securitytracker.com/id/1032781
http://www.debian.org/security/2015/dsa-3205
Related Vulnerabilities
CVE-2022-24437 Vulnerability in npm package git-pull-or-clone
CVE-2022-31367 Vulnerability in npm package @strapi/strapi
CVE-2020-13942 Vulnerability in maven package org.apache.unomi:unomi-services
CVE-2013-1571 Vulnerability in maven package org.apache.tomcat:catalina
CVE-2018-1002204 Vulnerability in maven package org.webjars.npm:adm-zip