Debian Security Advisory

DLA-182-1 batik -- LTS security update

Date Reported:
27 Mar 2015
Affected Packages:
batik
Vulnerable:
Yes
Security database references:
In the Debian bugtracking system: Bug 780897.
In Mitre's CVE dictionary: CVE-2015-0250.
More information:

Nicolas Gregoire and Kevin Schaller discovered that Batik, a toolkit for processing SVG images, would load XML external entities by default. If a user or automated system were tricked into opening a specially crafted SVG file, an attacker could possibly obtain access to arbitrary files or cause resource consumption.

For Debian 6 Squeeze, these issues have been fixed in batik version 1.7-6+deb6u1