CVE-2012-5656: Canonical Ubuntu Linux
Medium severity, CVSS 5.5. EPSS: 1.2% chance of exploitation in the next 30 days.
The rasterization process in Inkscape before 0.48.4 allows local users to read arbitrary files via an external entity in a SVG file, aka an XML external entity (XXE) injection attack.
Affected products
- Canonical Ubuntu Linux: version 10.04 only; version 11.10 only; version 12.04 only; version 12.10 only
- Fedoraproject Fedora: version 16 only; version 17 only; version 18 only
- Inkscape Inkscape: before 0.48.4 (fixed in 0.48.4)
- Opensuse Opensuse: version 11.4 only; version 12.1 only; version 12.2 only
Published 2013-01-18. Last modified 2026-06-16.