Логотип exploitDog
bind:CVE-2023-50251
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-50251

Количество 4

Количество 4

ubuntu логотип

CVE-2023-50251

около 2 лет назад

php-svg-lib is an SVG file parsing / rendering library. Prior to version 0.5.1, when parsing the attributes passed to a `use` tag inside an svg document, an attacker can cause the system to go to an infinite recursion. Depending on the system configuration and attack pattern this could exhaust the memory available to the executing process and/or to the server itself. An attacker sending multiple request to a system to render the above payload can potentially cause resource exhaustion to the point that the system is unable to handle incoming request. Version 0.5.1 contains a patch for this issue.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2023-50251

около 2 лет назад

php-svg-lib is an SVG file parsing / rendering library. Prior to version 0.5.1, when parsing the attributes passed to a `use` tag inside an svg document, an attacker can cause the system to go to an infinite recursion. Depending on the system configuration and attack pattern this could exhaust the memory available to the executing process and/or to the server itself. An attacker sending multiple request to a system to render the above payload can potentially cause resource exhaustion to the point that the system is unable to handle incoming request. Version 0.5.1 contains a patch for this issue.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2023-50251

около 2 лет назад

php-svg-lib is an SVG file parsing / rendering library. Prior to versi ...

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-ff5x-7qg5-vwf2

около 2 лет назад

Denial of service caused by infinite recursion when parsing SVG document

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2023-50251

php-svg-lib is an SVG file parsing / rendering library. Prior to version 0.5.1, when parsing the attributes passed to a `use` tag inside an svg document, an attacker can cause the system to go to an infinite recursion. Depending on the system configuration and attack pattern this could exhaust the memory available to the executing process and/or to the server itself. An attacker sending multiple request to a system to render the above payload can potentially cause resource exhaustion to the point that the system is unable to handle incoming request. Version 0.5.1 contains a patch for this issue.

CVSS3: 5.3
0%
Низкий
около 2 лет назад
nvd логотип
CVE-2023-50251

php-svg-lib is an SVG file parsing / rendering library. Prior to version 0.5.1, when parsing the attributes passed to a `use` tag inside an svg document, an attacker can cause the system to go to an infinite recursion. Depending on the system configuration and attack pattern this could exhaust the memory available to the executing process and/or to the server itself. An attacker sending multiple request to a system to render the above payload can potentially cause resource exhaustion to the point that the system is unable to handle incoming request. Version 0.5.1 contains a patch for this issue.

CVSS3: 5.3
0%
Низкий
около 2 лет назад
debian логотип
CVE-2023-50251

php-svg-lib is an SVG file parsing / rendering library. Prior to versi ...

CVSS3: 5.3
0%
Низкий
около 2 лет назад
github логотип
GHSA-ff5x-7qg5-vwf2

Denial of service caused by infinite recursion when parsing SVG document

CVSS3: 5.3
0%
Низкий
около 2 лет назад

Уязвимостей на страницу