Ubuntu Security Notice (C) 2014 Canonical, Inc. / NASL script (C) 2014 Tenable Network Security, Inc.
The remote Ubuntu host is missing a security-related patch.
It was discovered that librsvg would load XML external entities by
default. If a user were tricked into viewing a specially crafted SVG
file, an attacker could possibly obtain access to arbitrary files.
Update the affected librsvg2-2 package.
Risk factor :
Medium / CVSS Base Score : 4.3
CVSS Temporal Score : 3.7
Public Exploit Available : true