cvelist/2017/1000xxx/CVE-2017-1000498.json

1 line
833 B
JSON
Raw Normal View History

2017-12-29 13:54:10 -07:00
{"data_version": "4.0","references": {"reference_data": [{"url": "https://github.com/BigBadaboom/androidsvg/issues/122"}]},"description": {"description_data": [{"lang": "eng","value": "AndroidSVG version 1.2.2 is vulnerable to XXE attacks in the SVG parsing component resulting in denial of service and possibly remote code execution"}]},"data_type": "CVE","affects": {"vendor": {"vendor_data": [{"product": {"product_data": [{"version": {"version_data": [{"version_value": "1.2.2"}]},"product_name": "AndroidSVG"}]},"vendor_name": "AndroidSVG"}]}},"CVE_data_meta": {"DATE_ASSIGNED": "2017-12-29","ID": "CVE-2017-1000498","ASSIGNER": "kurt@seifried.org","REQUESTER": "sajeeb.lohani@bulletproof.sh"},"data_format": "MITRE","problemtype": {"problemtype_data": [{"description": [{"lang": "eng","value": "XML External Entity (XXE)"}]}]}}