Bug 922681 - (CVE-2015-0250) VUL-1: CVE-2015-0250: xmlgraphics-batik: Apache Batik information disclosure vulnerability
(CVE-2015-0250)
VUL-1: CVE-2015-0250: xmlgraphics-batik: Apache Batik information disclosure ...
Status: RESOLVED WONTFIX
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents
unspecified
Other Other
: P4 - Low : Normal
: ---
Assigned To: Thomas Schraitle
Security Team bot
CVSSv2:NVD:CVE-2015-0250:6.4:(AV:N/AC...
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2015-03-17 10:01 UTC by Marcus Meissner
Modified: 2021-02-25 16:26 UTC (History)
1 user (show)

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Marcus Meissner 2015-03-17 10:01:41 UTC
via bugtrqaq etc

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1


CVE-2015-0250:
        Apache Batik information disclosure vulnerability


Severity:
        Medium


Vendor:
        The Apache Software Foundation


Versions Affected:
        Batik 1.0 - 1.7


Description:
        Files lying on the filesystem of the server which uses batik can
        be revealed to arbitrary users who send maliciously formed SVG
        files. The file types that can be shown depend on the user context
        in which the exploitable application is running. If the user is root
        a full compromise of the server--including confidential or sensitive
        files--would be possible.

        XXE can also be used to attack the availability of the server
        via denial of service as the references within a xml document
        can trivially trigger an amplification attack.


Mitigation:
        Users should upgrade to Batik 1.8+


Credit:
        This issue was independently reported by Nicolas Gregoire of AGARRI
        (www.agarri.fr) and Kevin Schaller of ERNW (www.ernw.de).

References:
        http://xmlgraphics.apache.org/security.html

Luis Bernardo
Comment 1 Swamp Workflow Management 2015-03-17 23:00:32 UTC
bugbot adjusting priority
Comment 2 Gianluca Gabrielli 2021-02-25 16:26:45 UTC
SUSE:SLE-12:Update/xmlgraphics-batik (v. 1.7) is still vulnerable but no longer supported, while SUSE:SLE-12-SP3:Update/xmlgraphics-batik and SUSE:SLE-15-SP2:Update/xmlgraphics-batik are both supported and not affected.

I mark this issue as resolved.