Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2023-38633

Опубликовано: 22 июл. 2023
Источник: debian
EPSS Средний

Описание

A directory traversal problem in the URL decoder of librsvg before 2.56.3 could be used by local or remote attackers to disclose files (on the local filesystem outside of the expected area), as demonstrated by href=".?../../../../../../../../../../etc/passwd" in an xi:include element.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
librsvgfixed2.54.7+dfsg-1package
librsvgnot-affectedbusterpackage

Примечания

  • https://bugzilla.suse.com/show_bug.cgi?id=1213502

  • https://gitlab.gnome.org/GNOME/librsvg/-/issues/996

  • https://gitlab.gnome.org/GNOME/librsvg/-/commit/15293f1243e1dd4756ffc1d13d5a8ea49167174f (2.54.6)

  • https://gitlab.gnome.org/GNOME/librsvg/-/commit/d1f066bf2198bd46c5ba80cb5123b768ec16e37d (2.50.8)

  • https://gitlab.gnome.org/GNOME/librsvg/-/commit/22bcb919c8b39133370c7fc0eb27176fb09aa4fb (2.46.6)

  • https://www.openwall.com/lists/oss-security/2023/07/27/1

  • https://www.canva.dev/blog/engineering/when-url-parsers-disagree-cve-2023-38633/

EPSS

Процентиль: 97%
0.43614
Средний

Связанные уязвимости

CVSS3: 5.5
ubuntu
около 2 лет назад

A directory traversal problem in the URL decoder of librsvg before 2.56.3 could be used by local or remote attackers to disclose files (on the local filesystem outside of the expected area), as demonstrated by href=".?../../../../../../../../../../etc/passwd" in an xi:include element.

CVSS3: 5.5
redhat
около 2 лет назад

A directory traversal problem in the URL decoder of librsvg before 2.56.3 could be used by local or remote attackers to disclose files (on the local filesystem outside of the expected area), as demonstrated by href=".?../../../../../../../../../../etc/passwd" in an xi:include element.

CVSS3: 5.5
nvd
около 2 лет назад

A directory traversal problem in the URL decoder of librsvg before 2.56.3 could be used by local or remote attackers to disclose files (on the local filesystem outside of the expected area), as demonstrated by href=".?../../../../../../../../../../etc/passwd" in an xi:include element.

suse-cvrf
около 2 лет назад

Security update for librsvg

suse-cvrf
около 2 лет назад

Security update for librsvg

EPSS

Процентиль: 97%
0.43614
Средний