Candidate: CVE-2017-5617 PublicDate: 2017-03-16 15:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5617 https://github.com/blackears/svgSalamander/issues/11 http://www.openwall.com/lists/oss-security/2017/01/27/3 Description: The SVG Salamander (aka svgSalamander) library, when used in a web application, allows remote attackers to conduct server-side request forgery (SSRF) attacks via an xlink:href attribute in an SVG file. Ubuntu-Description: Notes: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=853134 Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N [7.4 HIGH] nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N [7.4 HIGH] Patches_svgsalamander: upstream_svgsalamander: released (1.1.1+dfsg-2) precise_svgsalamander: released (0~svn95-1+deb8u1build0.12.04.1) precise/esm_svgsalamander: DNE (precise was released [0~svn95-1+deb8u1build0.12.04.1]) trusty_svgsalamander: released (0~svn95-1+deb8u1build0.14.04.1) trusty/esm_svgsalamander: DNE (trusty was released [0~svn95-1+deb8u1build0.14.04.1]) vivid/stable-phone-overlay_svgsalamander: DNE vivid/ubuntu-core_svgsalamander: DNE xenial_svgsalamander: released (0~svn95-1+deb8u1build0.16.04.1) yakkety_svgsalamander: ignored (reached end-of-life) zesty_svgsalamander: not-affected (1.1.1+dfsg-2) devel_svgsalamander: not-affected (1.1.1+dfsg-2)