A vulnerability was found in the svgsalamander library. If the library is being used in a web application for processing user supplied SVG files then the app is vulnerable to SSRF (CVE-2017-5617). References: . MGASA-2019-0160 - Updated svgsalamander packages fix security vulnerability Publication date: 12 May 2019 URL: https://advisories.mageia.org/MGASA-2019-0160.html Type: security Affected Mageia releases: 6 CVE: CVE-2017-5617 A vulnerability was found in the svgsalamander library. If the library is being used in a web application for processing user supplied SVG files then the app is vulnerable to SSRF (CVE-2017-5617). References: - https://bugs.mageia.org/show_bug.cgi?id=24592 - https://lists.fedoraproject.org/archives/list/
New upstream release with security fix for CVE-2017-5617. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-735d3953e8 2019-03-29 19:07:28.734743 --------------------------------------------------------------------------------Name : svgsalamander Product : Fedora 30 Version : 1.1.2 Release : 1.fc30 URL : https://github.com/blackears/svgSalamander/ Summary : An SVG engine for Java Description : SVG Salamander is an SVG engine for Java that's designed to be small, fast, and allow programmers to use it with a minimum of fuss. It's in particular targeted for making it easy to integrate SVG into Java games and making it much easier for artists to design 2D game content - from rich interactive menus to charts and graphcs to complex animations. --------------------------------------------------------------------------------Update Information: New upstream release with security fix for CVE-2017-5617 --------------------------------------------------------------------------------References: [ 1 ] Bug #1417567 - CVE-2017-5617 svgsalamander: Server side request forgery via crafted scheme attributes https://bugzilla.redhat.com/show_bug.cgi?id=1417567 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-735d3953e8' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
New upstream release with security fix for CVE-2017-5617. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-3cbce64a64 2019-03-29 02:58:04.250073 --------------------------------------------------------------------------------Name : svgsalamander Product : Fedora 29 Version : 1.1.2 Release : 1.fc29 URL : https://github.com/blackears/svgSalamander/ Summary : An SVG engine for Java Description : SVG Salamander is an SVG engine for Java that's designed to be small, fast, and allow programmers to use it with a minimum of fuss. It's in particular targeted for making it easy to integrate SVG into Java games and making it much easier for artists to design 2D game content - from rich interactive menus to charts and graphcs to complex animations. --------------------------------------------------------------------------------Update Information: New upstream release with security fix for CVE-2017-5617 --------------------------------------------------------------------------------ChangeLog: * Fri Feb 15 2019 Jakub Jelen - 1.1.2-1 - New upstream release * Sun Feb 3 2019 Fedora Release Engineering - 1.1.1-6 - Rebuilt for https://fedoraproject.org/wiki/Fedora_30_Mass_Rebuild --------------------------------------------------------------------------------References: [ 1 ] Bug #1417567 - CVE-2017-5617 svgsalamander: Server side request forgery via crafted scheme attributes https://bugzilla.redhat.com/show_bug.cgi?id=1417567 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-3cbce64a64' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project canbe found at --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Luc Lynx discovered that SVG Salamander, a SVG engine for Java was susceptible to server side request forgery. For the stable distribution (jessie), this problem has been fixed in . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 - ------------------------------------------------------------------------- Debian Security Advisory DSA-3781-1
Get the latest Linux and open source security news straight to your inbox.