Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2023-38633

Опубликовано: 22 июл. 2023
Источник: ubuntu
Приоритет: medium
EPSS Средний
CVSS3: 5.5

Описание

A directory traversal problem in the URL decoder of librsvg before 2.56.3 could be used by local or remote attackers to disclose files (on the local filesystem outside of the expected area), as demonstrated by href=".?../../../../../../../../../../etc/passwd" in an xi:include element.

РелизСтатусПримечание
bionic

ignored

end of standard support
devel

released

2.54.5+dfsg-1ubuntu5
esm-infra/bionic

not-affected

code not present
esm-infra/focal

released

2.48.9-1ubuntu0.20.04.4
esm-infra/xenial

not-affected

code not present
focal

released

2.48.9-1ubuntu0.20.04.4
jammy

released

2.52.5+dfsg-3ubuntu0.2
lunar

released

2.54.5+dfsg-1ubuntu2.1
trusty

ignored

end of standard support
upstream

released

2.56.91,2.56.3,2.55.3,2.54.6,2.52.10,2.50.8,2.48.11,2.46.6

Показывать по

EPSS

Процентиль: 97%
0.43614
Средний

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
redhat
около 2 лет назад

A directory traversal problem in the URL decoder of librsvg before 2.56.3 could be used by local or remote attackers to disclose files (on the local filesystem outside of the expected area), as demonstrated by href=".?../../../../../../../../../../etc/passwd" in an xi:include element.

CVSS3: 5.5
nvd
около 2 лет назад

A directory traversal problem in the URL decoder of librsvg before 2.56.3 could be used by local or remote attackers to disclose files (on the local filesystem outside of the expected area), as demonstrated by href=".?../../../../../../../../../../etc/passwd" in an xi:include element.

CVSS3: 5.5
debian
около 2 лет назад

A directory traversal problem in the URL decoder of librsvg before 2.5 ...

suse-cvrf
около 2 лет назад

Security update for librsvg

suse-cvrf
около 2 лет назад

Security update for librsvg

EPSS

Процентиль: 97%
0.43614
Средний

5.5 Medium

CVSS3