perl-Image-Info: When parsing an SVG file, external entity expansion (XXE) was not disabled. An attacker could craft an SVG file which, when processed by an application using perl-Image-Info, could cause denial of service or, potentially, information disclosure.
CVSS Details
- CVSS 3.1 Base Score: 7.1
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade libimage-info-perl | Jul 30, 2024 | Dec 22, 2016 |
| Huawei Euleros 2_0_sp3 | — | — | Sep 28, 2020 | Dec 22, 2016 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Sep 27, 2016 |
| Suse | — | Upgrade perl-Image-Info | Mar 12, 2017 | Dec 22, 2016 |
| Ubuntu | — | No solution exists | Jun 26, 2025 | Dec 22, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub