Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-21236

Опубликовано: 06 янв. 2021
Источник: nvd
CVSS3: 5.7
CVSS3: 5.5
CVSS2: 4.3
EPSS Низкий

Описание

CairoSVG is a Python (pypi) package. CairoSVG is an SVG converter based on Cairo. In CairoSVG before version 2.5.1, there is a regular expression denial of service (REDoS) vulnerability. When processing SVG files, the python package CairoSVG uses two regular expressions which are vulnerable to Regular Expression Denial of Service (REDoS). If an attacker provides a malicious SVG, it can make cairosvg get stuck processing the file for a very long time. This is fixed in version 2.5.1. See Referenced GitHub advisory for more information.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:courtbouillon:cairosvg:*:*:*:*:*:*:*:*
Версия до 2.5.1 (исключая)

EPSS

Процентиль: 27%
0.00094
Низкий

5.7 Medium

CVSS3

5.5 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-400

Связанные уязвимости

CVSS3: 5.7
ubuntu
около 5 лет назад

CairoSVG is a Python (pypi) package. CairoSVG is an SVG converter based on Cairo. In CairoSVG before version 2.5.1, there is a regular expression denial of service (REDoS) vulnerability. When processing SVG files, the python package CairoSVG uses two regular expressions which are vulnerable to Regular Expression Denial of Service (REDoS). If an attacker provides a malicious SVG, it can make cairosvg get stuck processing the file for a very long time. This is fixed in version 2.5.1. See Referenced GitHub advisory for more information.

CVSS3: 5.7
debian
около 5 лет назад

CairoSVG is a Python (pypi) package. CairoSVG is an SVG converter base ...

CVSS3: 7.5
github
около 5 лет назад

Regular Expression Denial of Service in CairoSVG

suse-cvrf
больше 2 лет назад

Security update for python-CairoSVG

suse-cvrf
больше 2 лет назад

Security update for python-CairoSVG

EPSS

Процентиль: 27%
0.00094
Низкий

5.7 Medium

CVSS3

5.5 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-400