MGASA-2023-0259 - Updated librsvg packages fix security vulnerability

Publication date: 11 Sep 2023
URL: https://advisories.mageia.org/MGASA-2023-0259.html
Type: security
Affected Mageia releases: 8, 9
CVE: CVE-2023-38633

A directory traversal problem in the URL decoder of librsvg before 2.56.3
could be used by local or remote attackers to disclose files (on the local
filesystem outside of the expected area), as demonstrated by href="/.?../../../../../../../../../../etc/passwd" in an xi:include
element. (CVE-2023-38633)

References:
- https://bugs.mageia.org/show_bug.cgi?id=32210
- https://www.openwall.com/lists/oss-security/2023/07/27/1
- https://bugzilla.suse.com/show_bug.cgi?id=1213502
- https://gitlab.gnome.org/GNOME/librsvg/-/issues/996
- https://security-tracker.debian.org/tracker/CVE-2023-38633
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-38633

SRPMS:
- 8/core/librsvg-2.50.3-1.2.mga8
- 9/core/librsvg-2.56.0-1.1.mga9

Mageia 2023-0259: librsvg security update

A directory traversal problem in the URL decoder of librsvg before 2.56.3 could be used by local or remote attackers to disclose files (on the local filesystem outside of the expec...

Summary

A directory traversal problem in the URL decoder of librsvg before 2.56.3 could be used by local or remote attackers to disclose files (on the local filesystem outside of the expected area), as demonstrated by href="/.?../../../../../../../../../../etc/passwd" in an xi:include element. (CVE-2023-38633)

References

- https://bugs.mageia.org/show_bug.cgi?id=32210

- https://www.openwall.com/lists/oss-security/2023/07/27/1

- https://bugzilla.suse.com/show_bug.cgi?id=1213502

- https://gitlab.gnome.org/GNOME/librsvg/-/issues/996

- https://security-tracker.debian.org/tracker/CVE-2023-38633

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-38633

Resolution

MGASA-2023-0259 - Updated librsvg packages fix security vulnerability

SRPMS

- 8/core/librsvg-2.50.3-1.2.mga8

- 9/core/librsvg-2.56.0-1.1.mga9

Severity
Publication date: 11 Sep 2023
URL: https://advisories.mageia.org/MGASA-2023-0259.html
Type: security
CVE: CVE-2023-38633

Related News