inkscape (0.47.0-2ubuntu2.1) lucid-security; urgency=low

  * SECURITY UPDATE: arbitrary file disclosure via XML external entity
    - debian/patches/CVE-2012-5656.dpatch: disable loading external
      entities in src/preferences-skeleton.h,
      src/ui/dialog/ocaldialogs.cpp, src/xml/repr-io.cpp.
    - CVE-2012-5656
 -- Marc Deslauriers <email address hidden>   Tue, 29 Jan 2013 16:02:53 -0500

Marc Deslauriers on 2013-01-29
Ubuntu Developers
Lucid updates on 2013-01-30
Lucid security on 2013-01-30


File Size SHA-256 Checksum
inkscape_0.47.0.orig.tar.gz 26.7 MiB e5899be10183d86249516a29bc146706600ae5eafb5be5274c465a8029659b97
inkscape_0.47.0-2ubuntu2.1.diff.gz 22.9 KiB 41e09ac20b4ccc2841f6a4538f24da47ce00c25e6ba80a0011602c68ffee3cc0
inkscape_0.47.0-2ubuntu2.1.dsc 2.3 KiB 001e50f5d42fb57a17914c3f05696b3cdae948092eefa6bb40f3ea92356f084e

inkscape: vector-based drawing program

 Inkscape loads and saves a subset of the SVG (Scalable Vector Graphics)
 format, a standard maintained by the WWW consortium.
 Inkscape user interface should be familiar from CorelDraw and similar
 drawing programs. There are rectangles, ellipses, text items, bitmap
 images and freehand curves.
 As an added bonus, both vector and bitmap objects can have alpha
 transparency and can be arbitrarily transformed.
 Inkscape supports multiple opened files and multiple views per file.
 Graphics can be printed and exported to png bitmaps.
 Some of the import and export features are provided using the packages
 dia, libwmf-bin, pstoedit, skencil, imagemagick, and perlmagick.
 Other extensions use ruby, libxml-xql-perl, python-numpy, and python-lxml.
 You must have these packages to make full use of all extensions and effects.
 If you want to use the spellchecker, you have to install aspell and the
 respective language-pack, e.g. aspell-en or aspell-de.