6.3 MEDIUM
- CVSS version: 3.1
- Attack vector (AV): LOCAL
- Attack complexity (AC): LOW
- Privileges required (PR): NONE
- User interaction (UI): REQUIRED
- Scope (S): CHANGED
- Confidentiality impact (C): HIGH
- Integrity impact (I): NONE
- Availability impact (A): NONE
Improper Restriction of XML External Entity Reference in Inkscape
A local file disclosure vulnerability in the XInclude processing component of Inkscape 1.1 before 1.3 allows a remote attacker to read local files via a crafted SVG file containing malicious xi:include tags.
References
Affected products
- <1.3
Matching in nixpkgs
pkgs.inkscape
Vector graphics editor
pkgs.inkscape-with-extensions
Vector graphics editor
pkgs.inkscape-extensions.inkcut
None
pkgs.inkscape-extensions.silhouette
Extension to drive Silhouette vinyl cutters (e.g. Cameo, Portrait, Curio series) from within Inkscape
pkgs.inkscape-extensions.applytransforms
Inkscape extension which removes all matrix transforms by applying them recursively to shapes
-
nixos-unstable 0.pre+unstable=2021-05-11
- nixpkgs-unstable 0.pre+unstable=2021-05-11
- nixos-unstable-small 0.pre+unstable=2021-05-11
-
nixos-25.11 0.pre+unstable=2021-05-11
- nixos-25.11-small 0.pre+unstable=2021-05-11
- nixpkgs-25.11-darwin 0.pre+unstable=2021-05-11
Package maintainers
-
@x123 x123 <nix@nixlink.net>
-
@jtojnar Jan Tojnar <jtojnar@gmail.com>
-
@Luflosi Luflosi <luflosi@luflosi.de>
-
@jfly Jeremy Fleischman <jeremyfleischman@gmail.com>