Alerts This Week
Warning Icon 1 560
Alerts This Week
Warning Icon 1 560

Mageia: 2021-0144 Moderate: xmlgraphics-commons SSRF Risk Advisory

mageia
Calendar Grey March 18, 2021
Dist Mageia Esm H88
Mageia 2021-0145 patches xmlgraphics-commons to address SSRF vulnerability through XMPParser, enabling unauthorized GET requests.
The Apache XML Graphics Commons library is vulnerable to SSRF via the XMPParser that allow an attacker to cause the underlying server to make arbitrary GET requests (CVE-2020-11988...

Summary

The Apache XML Graphics Commons library is vulnerable to SSRF via the XMPParser that allow an attacker to cause the underlying server to make arbitrary GET requests (CVE-2020-11988).

References

- https://bugs.mageia.org/show_bug.cgi?id=28440

- https://www.openwall.com/lists/oss-security/2021/02/24/1

- https://xmlgraphics.apache.org/security.html

- https://www.cve.org/CVERecord?id=CVE-2020-11988

Resolution

SRPMS

- 7/core/xmlgraphics-commons-2.6-1.mga7

- 8/core/xmlgraphics-commons-2.6-1.mga8

Publication date: 18 Mar 2021
URL: https://advisories.mageia.org/MGASA-2021-0144.html
Type: security
CVE: CVE-2020-11988

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here