Description
LatexDraw version <=4.0 contains a XML External Entity (XXE) vulnerability in SVG parsing functionality that can result in disclosure of data, server side request forgery, port scanning, possible rce. This attack appear to be exploitable via Specially crafted SVG file.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-1973 | LatexDraw version <=4.0 contains a XML External Entity (XXE) vulnerability in SVG parsing functionality that can result in disclosure of data, server side request forgery, port scanning, possible rce. This attack appear to be exploitable via Specially crafted SVG file. |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-09-17T04:25:03.167Z
Reserved: 2018-08-20T00:00:00.000Z
Link: CVE-2018-1000639
No data.
Status : Modified
Published: 2018-08-20T19:31:35.497
Modified: 2024-11-21T03:40:18.057
Link: CVE-2018-1000639
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD