Permissions, Privileges, and Access Controls in inkscape - CVE-2012-6076

 

Permissions, Privileges, and Access Controls in inkscape - CVE-2012-6076

Published: March 13, 2013 / Updated: August 11, 2020


Vulnerability identifier: #VU43010
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2012-6076
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

Inkscape before 0.48.4 reads .eps files from /tmp instead of the current directory, which might cause Inkspace to process unintended files, allow local users to obtain sensitive information, and possibly have other unspecified impacts.


Affected software

inkscape

How to mitigate CVE-2012-6076

Install update from vendor's website.


External References

Related Security Bulletins