A vulnerability was found in the svgsalamander library. If the library is
being used in a web application for processing user supplied SVG files then
the app is vulnerable to SSRF (CVE-2017-5617).
- https://bugs.mageia.org/show_bug.cgi?id=24592
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/UPUOI6NCEB6H6YHKN7M4V3CAQD63NXAU/
- https://www.cve.org/CVERecord?id=CVE-2017-5617
- 6/core/svgsalamander-1.1.2-1.mga6
Get the latest Linux and open source security news straight to your inbox.