Ubuntu Security Notice (C) 2014 Canonical, Inc. / NASL script (C) 2014 Tenable Network Security, Inc.
The remote Ubuntu host is missing a security-related patch.
USN-2149-1 fixed a vulnerability in librsvg. This update provides a
compatibility fix for GTK+ to work with the librsvg security update.
It was discovered that librsvg would load XML external entities by
default. If a user were tricked into viewing a specially crafted SVG
file, an attacker could possibly obtain access to arbitrary files.
Update the affected libgtk-3-0 package.
Risk factor :
Medium / CVSS Base Score : 4.3
CVSS Temporal Score : 3.7
Public Exploit Available : true