Vulnerabilities > CVE-2016-9181 - XXE vulnerability in Image-Info Project Image-Info for Perl 1.16/1.30

047910
CVSS 5.8 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
PARTIAL

Summary

perl-Image-Info: When parsing an SVG file, external entity expansion (XXE) was not disabled. An attacker could craft an SVG file which, when processed by an application using perl-Image-Info, could cause denial of service or, potentially, information disclosure.

Nessus

NASL familySuSE Local Security Checks
NASL idOPENSUSE-2017-327.NASL
descriptionThis update for perl-Image-Info fixes the following issues : - update to version 1.39 to fix a potential security issue. A crafted SVG file could have caused information disclosure or denial of service by using external entitity expansion (XXE). This is a potentially incompatible change; however usually SVG files do not rely on XXE. (boo#1008647, CVE-2016-9181)
last seen2020-06-05
modified2017-03-14
plugin id97710
published2017-03-14
reporterThis script is Copyright (C) 2017-2020 Tenable Network Security, Inc.
sourcehttps://www.tenable.com/plugins/nessus/97710
titleopenSUSE Security Update : perl-Image-Info (openSUSE-2017-327)