header-logo
Suggest Exploit
vendor:
N/A
by:
Nicolas Grégoire
8,8
CVSS
HIGH
SVG File Format Vulnerability
79
CWE
Product Name: N/A
Affected Version From: SVG 1.1 and SVG Tiny 1.2
Affected Version To: SVG 1.1 and SVG Tiny 1.2
Patch Exists: No
Related CWE: N/A
CPE: N/A
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2020

SVG File Format Vulnerability

SVG is a XML-based file format for static or animated images. Some SVG specifications (like SVG 1.1 and SVG Tiny 1.2) allow to trigger some Java code when the SVG file is opened. PoC codes are available online at http://www.agarri.fr/docs/batik-evil.svg and https://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/18890.svg

Mitigation:

Disable SVG support in the application or use a secure parser for SVG files.
Source

Exploit-DB raw data:

SVG is a XML-based file format for static or animated images. Some SVG
specifications (like  SVG 1.1 and SVG Tiny 1.2) allow to trigger some
Java code when the SVG file is opened.

Given that I had to look at these features for a customer, I developed
some PoC codes which are now available online:

http://www.agarri.fr/docs/batik-evil.svg
http://www.agarri.fr/docs/batik-evil.jar

https://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/18890.svg
https://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/18890.jar

I published a more detailed article on my blog:
http://www.agarri.fr/blog/

Regards,
Nicolas Grégoire / @Agarri_FR