CVE-2012-5656: Canonical Ubuntu Linux

Medium severity, CVSS 5.5. EPSS: 1.2% chance of exploitation in the next 30 days.

The rasterization process in Inkscape before 0.48.4 allows local users to read arbitrary files via an external entity in a SVG file, aka an XML external entity (XXE) injection attack.

Affected products

  • Canonical Ubuntu Linux: version 10.04 only; version 11.10 only; version 12.04 only; version 12.10 only
  • Fedoraproject Fedora: version 16 only; version 17 only; version 18 only
  • Inkscape Inkscape: before 0.48.4 (fixed in 0.48.4)
  • Opensuse Opensuse: version 11.4 only; version 12.1 only; version 12.2 only

Published 2013-01-18. Last modified 2026-06-16.