{"affected":[{"ecosystem_specific":{"binaries":[{"librsvg-devel":"2.26.0-2.5.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Software Development Kit 11 SP3","name":"librsvg","purl":"pkg:rpm/suse/librsvg&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2011%20SP3"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.26.0-2.5.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"librsvg-devel":"2.26.0-2.5.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Software Development Kit 11 SP4","name":"librsvg","purl":"pkg:rpm/suse/librsvg&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2011%20SP4"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.26.0-2.5.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"librsvg":"2.26.0-2.5.1","librsvg-32bit":"2.26.0-2.5.1","rsvg-view":"2.26.0-2.5.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Desktop 11 SP3","name":"librsvg","purl":"pkg:rpm/suse/librsvg&distro=SUSE%20Linux%20Enterprise%20Desktop%2011%20SP3"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.26.0-2.5.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"librsvg":"2.26.0-2.5.1","librsvg-32bit":"2.26.0-2.5.1","rsvg-view":"2.26.0-2.5.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Desktop 11 SP4","name":"librsvg","purl":"pkg:rpm/suse/librsvg&distro=SUSE%20Linux%20Enterprise%20Desktop%2011%20SP4"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.26.0-2.5.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"librsvg":"2.26.0-2.5.1","librsvg-32bit":"2.26.0-2.5.1","librsvg-x86":"2.26.0-2.5.1","rsvg-view":"2.26.0-2.5.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server 11 SP3","name":"librsvg","purl":"pkg:rpm/suse/librsvg&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP3"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.26.0-2.5.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"librsvg":"2.26.0-2.5.1","librsvg-32bit":"2.26.0-2.5.1","librsvg-x86":"2.26.0-2.5.1","rsvg-view":"2.26.0-2.5.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server 11 SP3-TERADATA","name":"librsvg","purl":"pkg:rpm/suse/librsvg&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP3-TERADATA"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.26.0-2.5.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"librsvg":"2.26.0-2.5.1","librsvg-32bit":"2.26.0-2.5.1","librsvg-x86":"2.26.0-2.5.1","rsvg-view":"2.26.0-2.5.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 11 SP3","name":"librsvg","purl":"pkg:rpm/suse/librsvg&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2011%20SP3"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.26.0-2.5.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"librsvg":"2.26.0-2.5.1","librsvg-32bit":"2.26.0-2.5.1","librsvg-x86":"2.26.0-2.5.1","rsvg-view":"2.26.0-2.5.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server 11 SP4","name":"librsvg","purl":"pkg:rpm/suse/librsvg&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.26.0-2.5.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"librsvg":"2.26.0-2.5.1","librsvg-32bit":"2.26.0-2.5.1","librsvg-x86":"2.26.0-2.5.1","rsvg-view":"2.26.0-2.5.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 11 SP4","name":"librsvg","purl":"pkg:rpm/suse/librsvg&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2011%20SP4"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.26.0-2.5.1"}],"type":"ECOSYSTEM"}]}],"aliases":[],"details":"librsvg was updated to fix one security issue.\n\nThis security issue was fixed:\n- CVE-2013-1881: GNOME libsvg allowed remote attackers to read arbitrary files via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue (bsc#840753).\n  ","id":"SUSE-SU-2015:1785-1","modified":"2015-10-12T08:30:54Z","published":"2015-10-12T08:30:54Z","references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2015/suse-su-20151785-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/840753"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2013-1881"}],"related":["CVE-2013-1881"],"summary":"Security update for librsvg","upstream":["CVE-2013-1881"]}