ELA-237-1 batik security update

Server-side request forgery

2020-07-02
Packagebatik
Version1.7+dfsg-5+deb8u2
Related CVEs CVE-2019-17566


The Apache Batik library can be made to perform arbitrary GET requests via xlink:href attributes on SVG files. Since there can be legitimate use cases for xlink:href attributes, this update introduces a new option, -blockExternalResources, that can be used to prevent fetching external resources.



For Debian 8 jessie, these problems have been fixed in version 1.7+dfsg-5+deb8u2.

We recommend that you upgrade your batik packages.

Further information about Extended LTS security advisories can be found in the dedicated section of our website.