High severity7.1NVD Advisory· Published Dec 22, 2016· Updated May 6, 2026
CVE-2016-9181
CVE-2016-9181
Description
perl-Image-Info: When parsing an SVG file, external entity expansion (XXE) was not disabled. An attacker could craft an SVG file which, when processed by an application using perl-Image-Info, could cause denial of service or, potentially, information disclosure.
Affected products
2cpe:2.3:a:image-info_project:image-info_for_perl:1.16:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:image-info_project:image-info_for_perl:1.16:*:*:*:*:*:*:*
- cpe:2.3:a:image-info_project:image-info_for_perl:1.30:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- www.openwall.com/lists/oss-security/2016/11/04/2nvdThird Party Advisory
- www.securityfocus.com/bid/94220nvdThird Party AdvisoryVDB Entry
- bugzilla.redhat.com/show_bug.cginvdThird Party AdvisoryVDB Entry
News mentions
0No linked articles in our index yet.