Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-21236

Опубликовано: 06 янв. 2021
Источник: debian
EPSS Низкий

Описание

CairoSVG is a Python (pypi) package. CairoSVG is an SVG converter based on Cairo. In CairoSVG before version 2.5.1, there is a regular expression denial of service (REDoS) vulnerability. When processing SVG files, the python package CairoSVG uses two regular expressions which are vulnerable to Regular Expression Denial of Service (REDoS). If an attacker provides a malicious SVG, it can make cairosvg get stuck processing the file for a very long time. This is fixed in version 2.5.1. See Referenced GitHub advisory for more information.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
cairosvgfixed2.5.0-1.1package
cairosvgnot-affectedbusterpackage
cairosvgnot-affectedstretchpackage

Примечания

  • https://github.com/Kozea/CairoSVG/security/advisories/GHSA-hq37-853p-g5cf

  • Introduced by: https://github.com/Kozea/CairoSVG/commit/4f14d2e8f2d7f9b534c5342e26519b7c27386a81

  • Fixed by: https://github.com/Kozea/CairoSVG/commit/063185b60588a41d4df661ad70f9f7b699901abc (2.5.1)

EPSS

Процентиль: 27%
0.00094
Низкий

Связанные уязвимости

CVSS3: 5.7
ubuntu
около 5 лет назад

CairoSVG is a Python (pypi) package. CairoSVG is an SVG converter based on Cairo. In CairoSVG before version 2.5.1, there is a regular expression denial of service (REDoS) vulnerability. When processing SVG files, the python package CairoSVG uses two regular expressions which are vulnerable to Regular Expression Denial of Service (REDoS). If an attacker provides a malicious SVG, it can make cairosvg get stuck processing the file for a very long time. This is fixed in version 2.5.1. See Referenced GitHub advisory for more information.

CVSS3: 5.7
nvd
около 5 лет назад

CairoSVG is a Python (pypi) package. CairoSVG is an SVG converter based on Cairo. In CairoSVG before version 2.5.1, there is a regular expression denial of service (REDoS) vulnerability. When processing SVG files, the python package CairoSVG uses two regular expressions which are vulnerable to Regular Expression Denial of Service (REDoS). If an attacker provides a malicious SVG, it can make cairosvg get stuck processing the file for a very long time. This is fixed in version 2.5.1. See Referenced GitHub advisory for more information.

CVSS3: 7.5
github
около 5 лет назад

Regular Expression Denial of Service in CairoSVG

suse-cvrf
больше 2 лет назад

Security update for python-CairoSVG

suse-cvrf
больше 2 лет назад

Security update for python-CairoSVG

EPSS

Процентиль: 27%
0.00094
Низкий