The rasterization process in Inkscape before 0.48.4 allows local users to read arbitrary files via an external entity in a SVG file, aka an XML external entity (XXE) injection attack.
History

Wed, 16 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00097}

epss

{'score': 0.00052}


Sun, 13 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.0016}

epss

{'score': 0.00097}


cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2024-08-06T21:14:16.440Z

Reserved: 2012-10-24T00:00:00.000Z

Link: CVE-2012-5656

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2013-01-18T11:48:40.323

Modified: 2026-04-29T01:13:23.040

Link: CVE-2012-5656

cve-icon Redhat

Severity : Low

Publid Date: 2012-12-17T00:00:00Z

Links: CVE-2012-5656 - Bugzilla

cve-icon OpenCVE Enrichment

No data.