Vulnerability Details CVE-2016-9181
perl-Image-Info: When parsing an SVG file, external entity expansion (XXE) was not disabled. An attacker could craft an SVG file which, when processed by an application using perl-Image-Info, could cause denial of service or, potentially, information disclosure.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 48.6%
CVSS Severity
CVSS v3 Score 7.1
CVSS v2 Score 5.8
Products affected by CVE-2016-9181
-
cpe:2.3:a:image-info_project:image-info_for_perl:1.16
-
cpe:2.3:a:image-info_project:image-info_for_perl:1.30