Back

MEDIUM

librsvg2: local resource access vulnerability due to XML External Entity enablement

Published Oct 10, 2013

Description

GNOME libsvg before 2.39.0 allows remote attackers to read arbitrary files via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

Affected products

Remediation

Red Hat statement

This issue did not affect the versions of librsvg2 as shipped with Red Hat Enterprise Linux 5.

Metrics

References (13)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Oct 10, 2013
Updated Aug 6, 2024
Reserved Feb 19, 2013
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Moderate
Public date Aug 17, 2013