Vulnerabilities > CVE-2016-9181 - XXE vulnerability in Image-Info Project Image-Info for Perl 1.16/1.30

047910
CVSS 7.1 - HIGH
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
HIGH
local
low complexity
image-info-project
CWE-611
nessus

Summary

perl-Image-Info: When parsing an SVG file, external entity expansion (XXE) was not disabled. An attacker could craft an SVG file which, when processed by an application using perl-Image-Info, could cause denial of service or, potentially, information disclosure.

Nessus

NASL familySuSE Local Security Checks
NASL idOPENSUSE-2017-327.NASL
descriptionThis update for perl-Image-Info fixes the following issues : - update to version 1.39 to fix a potential security issue. A crafted SVG file could have caused information disclosure or denial of service by using external entitity expansion (XXE). This is a potentially incompatible change; however usually SVG files do not rely on XXE. (boo#1008647, CVE-2016-9181)
last seen2020-06-05
modified2017-03-14
plugin id97710
published2017-03-14
reporterThis script is Copyright (C) 2017-2020 Tenable Network Security, Inc.
sourcehttps://www.tenable.com/plugins/nessus/97710
titleopenSUSE Security Update : perl-Image-Info (openSUSE-2017-327)