Apache Batik Information Leakage Vulnerability (CVE-2015-0250)
Release date:
Updated on:
Affected Systems:
Apache Group Batik <1.8
Description:
CVE (CAN) ID: CVE-2015-0250
Batik is a Java-based application toolkit that uses the SVG format for multiple purposes, such as viewing, controlling, or manipulating.
In versions earlier than Apache Batik 1.8, the XML external entity vulnerability exists when converting SVG to PNG or JPG. By constructing SVG files, remote attackers can read files or cause DOS.
<* Source: Timo Schmid
Link: http://seclists.org/fulldisclosure/2015/Mar/142
*>
Suggestion:
Vendor patch:
Apache Group
------------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
[1] http://xmlgraphics.apache.org/batik/
[2]
Http://www.insinuator.net/2015/03/xxe-injection-in-apache-batik-library-cve-2015-0250/
[3] https://www.owasp.org/index.php/XML_External_Entity_%28XXE%29_Processing
[4] https://www.ernw.de/download/xxe_batik.tar.xz
This article permanently updates the link address: