PT-2018-5262 · Google · Androidsvg
Prodigysml
·
Publicado
2018-01-03
·
Atualizado
2020-01-30
·
CVE-2017-1000498
CVSS v3.1
7.8
Alta
| Vetor | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
AndroidSVG version 1.2.2
Description
The issue affects the SVG parsing component, making it vulnerable to XXE attacks. This can result in denial of service and possibly remote code execution.
Recommendations
For AndroidSVG version 1.2.2, update to a version that fixes the XXE vulnerability in the SVG parsing component to prevent denial of service and potential remote code execution.
Correção
XXE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Androidsvg