Executive Summary
Summary | |
---|---|
Title | New Inkscape packages fix arbitrary code execution |
Informations | |||
---|---|---|---|
Name | DSA-916 | First vendor Publication | 2005-12-07 |
Vendor | Debian | Last vendor Modification | 2005-12-07 |
Severity (Vendor) | N/A | Revision | 1 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:H/Au:N/C:P/I:P/A:P) | |||
---|---|---|---|
Cvss Base Score | 5.1 | Attack Range | Network |
Cvss Impact Score | 6.4 | Attack Complexity | High |
Cvss Expoit Score | 4.9 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
Several vulnerabilities have been discovered in Inkscape, a vector-based drawing program. The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2005-3737 Joxean Koret discovered a buffer overflow in the SVG parsing routines that can lead to the execution of arbitrary code. CVE-2005-3885 Javier Fernández-Sanguino Peña noticed that the ps2epsi extension shell script uses a hardcoded temporary file making it vulnerable to symlink attacks. The old stable distribution (woody) does not contain inkscape packages. For the stable distribution (sarge) this problem has been fixed in version 0.41-4.99.sarge2. For the unstable distribution (sid) this problem has been fixed in version 0.42.2+0.43pre1-1. We recommend that you upgrade your inkscape package. |
Original Source
Url : http://www.debian.org/security/2005/dsa-916 |
CPE : Common Platform Enumeration
Type | Description | Count |
---|---|---|
Application | 4 |
OpenVAS Exploits
Date | Description |
---|---|
2008-09-24 | Name : Gentoo Security Advisory GLSA 200511-22 (Inkscape) File : nvt/glsa_200511_22.nasl |
2008-01-17 | Name : Debian Security Advisory DSA 916-1 (inkscape) File : nvt/deb_916_1.nasl |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
21001 | Inkspace SVG Importer Overflow |
18636 | Inkscape ps2epsi.sh Symlink Arbitrary File Overwrite |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2006-10-14 | Name : The remote Debian host is missing a security-related update. File : debian_DSA-916.nasl - Type : ACT_GATHER_INFO |
2006-01-21 | Name : The remote Ubuntu host is missing a security-related patch. File : ubuntu_USN-223-1.nasl - Type : ACT_GATHER_INFO |
2005-12-07 | Name : The remote Gentoo host is missing one or more security-related patches. File : gentoo_GLSA-200511-22.nasl - Type : ACT_GATHER_INFO |
Alert History
Date | Informations |
---|---|
2014-02-17 11:34:43 |
|