Security Advisories (1)
CVE-2016-9181 (2016-11-04)

perl-Image-Info: When parsing an SVG file, external entity expansion (XXE) was not disabled. An attacker could craft an SVG file which, when processed by an application using perl-Image-Info, could cause denial of service or, potentially, information disclosure.

Provides

in lib/Image/Info.pm
in lib/Image/Info/GIF.pm
in lib/Image/Info/JPEG.pm
in lib/Image/Info/PNG.pm
in lib/Image/Info.pm
in lib/Image/TIFF.pm
in lib/Image/TIFF/Exif.pm