CVE-2012-6076
Publication date 31 December 2012
Last updated 24 July 2024
Ubuntu priority
Inkscape before 0.48.4 reads .eps files from /tmp instead of the current directory, which might cause Inkspace to process unintended files, allow local users to obtain sensitive information, and possibly have other unspecified impacts.
Status
Package | Ubuntu Release | Status |
---|---|---|
inkscape | ||
Notes
seth-arnold
"low" priority due to symlink and hardlink restrictions in Ubuntu's Linux kernels; without those protections, "medium" would be more appropriate. Multiple patches are proposed in the bugreport; NewAndUndoOld appears to be preferred from comments #11 and #12
mdeslaur
0.48.4 has fix, albeit the older fix. inkscape in lucid doesn't do the chdir into /tmp, so not-affected
Patch details
Package | Patch details |
---|---|
inkscape |
References
Related Ubuntu Security Notices (USN)
- USN-1712-1
- Inkscape vulnerabilities
- 30 January 2013