Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

Mageia 8 and 9 Security Advisory: Librsvg Directory Traversal Risk

mageia
Calendar Grey September 11, 2023
Dist Mageia Esm H88
Librsvg enhancement resolves path traversal vulnerability impacting local files. Discover further details in the security briefing.
A directory traversal problem in the URL decoder of librsvg before 2.56.3 could be used by local or remote attackers to disclose files (on the local filesystem outside of the expec...

Summary

A directory traversal problem in the URL decoder of librsvg before 2.56.3 could be used by local or remote attackers to disclose files (on the local filesystem outside of the expected area), as demonstrated by href="/.?../../../../../../../../../../etc/passwd" in an xi:include element. (CVE-2023-38633)

References

- https://bugs.mageia.org/show_bug.cgi?id=32210

- https://www.openwall.com/lists/oss-security/2023/07/27/1

- https://bugzilla.suse.com/show_bug.cgi?id=1213502

-

- https://security-tracker.debian.org/tracker/CVE-2023-38633

- https://www.cve.org/CVERecord?id=CVE-2023-38633

Resolution

SRPMS

- 8/core/librsvg-2.50.3-1.2.mga8

- 9/core/librsvg-2.56.0-1.1.mga9

Severity
important
Lowest
Low
Medium
High
Critical

Publication date: 11 Sep 2023
URL: https://advisories.mageia.org/MGASA-2023-0259.html
Type: security
CVE: CVE-2023-38633

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here