Vulnerability Bulletins

DSA-3205 batik - security update

   
Affected software Debian
 
Nicolas Gregoire and Kevin Schaller discovered that Batik, a toolkitfor processing SVG images, would load XML external entities bydefault. If a user or automated system were tricked into opening aspecially crafted SVG file, an attacker could possibly obtain accessto arbitrary files or cause resource consumption.

More info:

https://www.debian.org/security/2015/dsa-3205