CVE-2016-9181: Image-Info Project Image-Info For Perl
High severity, CVSS 7.1. EPSS: 1.2% chance of exploitation in the next 30 days.
perl-Image-Info: When parsing an SVG file, external entity expansion (XXE) was not disabled. An attacker could craft an SVG file which, when processed by an application using perl-Image-Info, could cause denial of service or, potentially, information disclosure.
Affected products
- Image-Info Project Image-Info For Perl: version 1.16 only; version 1.30 only
Published 2016-12-22. Last modified 2026-06-17.