Description
XML external entity (XXE) vulnerability in the SVG to (1) PNG and (2) JPG conversion classes in Apache Batik 1.x before 1.8 allows remote attackers to read arbitrary files or cause a denial of service via a crafted SVG file.
Remediation
References
http://seclists.org/fulldisclosure/2015/Mar/142
http://xmlgraphics.apache.org/security.html
http://www.ubuntu.com/usn/USN-2548-1
http://packetstormsecurity.com/files/130964/Apache-Batik-XXE-Injection.html
http://www.mandriva.com/security/advisories?name=MDVSA-2015:203
http://advisories.mageia.org/MGASA-2015-0138.html
http://rhn.redhat.com/errata/RHSA-2016-0041.html
http://rhn.redhat.com/errata/RHSA-2016-0042.html
http://www-01.ibm.com/support/docview.wss?uid=swg21963275
http://www.securitytracker.com/id/1032781
http://www.debian.org/security/2015/dsa-3205
Related Vulnerabilities
CVE-2023-39154 Vulnerability in maven package com.qualys.plugins:qualys-was
CVE-2021-23434 Vulnerability in npm package object-path
CVE-2022-31160 Vulnerability in maven package org.webjars.npm:jquery-ui
CVE-2023-27848 Vulnerability in npm package broccoli-compass
CVE-2022-36090 Vulnerability in maven package org.xwiki.platform:xwiki-platform-oldcore