Lucene search

K
debianDebianDEBIAN:DLA-182-1:55F71
HistoryMar 27, 2015 - 9:16 p.m.

[SECURITY] [DLA 182-1] batik security update

2015-03-2721:16:06
lists.debian.org
14

6.4 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:N/A:P

8.8 High

AI Score

Confidence

High

0.043 Low

EPSS

Percentile

92.3%

Package : batik
Version : 1.7-6+deb6u1
CVE ID : CVE-2015-0250
Debian Bug : 780897

Nicolas Gregoire and Kevin Schaller discovered that Batik, a toolkit
for processing SVG images, would load XML external entities by
default. If a user or automated system were tricked into opening a
specially crafted SVG file, an attacker could possibly obtain access
to arbitrary files or cause resource consumption.

6.4 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:N/A:P

8.8 High

AI Score

Confidence

High

0.043 Low

EPSS

Percentile

92.3%