Medium severity5.5NVD Advisory· Published Jan 18, 2013· Updated Apr 29, 2026
CVE-2012-5656
CVE-2012-5656
Description
The rasterization process in Inkscape before 0.48.4 allows local users to read arbitrary files via an external entity in a SVG file, aka an XML external entity (XXE) injection attack.
Affected products
11cpe:2.3:o:canonical:ubuntu_linux:10.04:*:*:*:-:*:*:*+ 3 more
- cpe:2.3:o:canonical:ubuntu_linux:10.04:*:*:*:-:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:11.10:*:*:*:*:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:-:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:12.10:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:16:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:o:fedoraproject:fedora:16:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:17:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:18:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
11- bazaar.launchpad.net/~inkscape.dev/inkscape/trunk/revision/11931nvdPatch
- www.openwall.com/lists/oss-security/2012/12/20/3nvdExploitMailing List
- bugs.launchpad.net/inkscape/+bug/1025185nvdExploitIssue Tracking
- www.securityfocus.com/bid/56965nvdBroken LinkThird Party AdvisoryVDB Entry
- www.ubuntu.com/usn/USN-1712-1nvdThird Party Advisory
- lists.fedoraproject.org/pipermail/package-announce/2012-December/095024.htmlnvdMailing List
- lists.fedoraproject.org/pipermail/package-announce/2013-January/095380.htmlnvdMailing List
- lists.fedoraproject.org/pipermail/package-announce/2013-January/095398.htmlnvdMailing List
- lists.opensuse.org/opensuse-updates/2013-02/msg00041.htmlnvdMailing List
- lists.opensuse.org/opensuse-updates/2013-02/msg00043.htmlnvdMailing List
- launchpad.net/inkscape/+milestone/0.48.4nvdProduct
News mentions
0No linked articles in our index yet.