CVE-2015-0250
Summary
| CVE | CVE-2015-0250 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2015-03-24 17:59:00 UTC |
| Updated | 2017-11-04 01:29:00 UTC |
| Description | XML external entity (XXE) vulnerability in the SVG to (1) PNG and (2) JPG conversion classes in Apache Batik 1.x before 1.8 allows remote attackers to read arbitrary files or cause a denial of service via a crafted SVG file. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Apache | Batik | All | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 12.04 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 14.04 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 14.10 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 12.04 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 14.04 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 14.10 | All | All | All |
| Application | Redhat | Jboss Enterprise Brms Platform | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Red Hat Customer Portal | REDHAT | rhn.redhat.com | |
| The Apache™ XML Graphics Project - Community | CONFIRM | xmlgraphics.apache.org | Vendor Advisory |
| Apache Batik XXE Injection ≈ Packet Storm | MISC | packetstormsecurity.com | |
| Debian -- Security Information -- DSA-3205-1 batik | DEBIAN | www.debian.org | |
| USN-2548-1: Batik vulnerability | Ubuntu | UBUNTU | www.ubuntu.com | Patch |
| Mageia Advisory: MGASA-2015-0138 - Updated batik packages fix security vulnerabilities | CONFIRM | advisories.mageia.org | |
| Full Disclosure: [CVE-2015-0250] Apache Batik Information Disclosure Vulnerability (XXE Injection) | FULLDISC | seclists.org | Exploit |
| Apache Batik XML External Entity Processing Flaw Lets Remote Users Obtain Potentially Sensitive Information - SecurityTracker | SECTRACK | www.securitytracker.com | |
| IBM Security Bulletin: Multiple Security Vulnerabilities fixed in IBM WebSphere Application Server 8.0.0.11 - United States | CONFIRM | www-01.ibm.com | |
| Support / Security / Advisories / / MDVSA-2015:203 | Mandriva | MANDRIVA | www.mandriva.com | |
| Red Hat Customer Portal | REDHAT | rhn.redhat.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.