Description
A directory traversal problem in the URL decoder of librsvg before 2.56.3 could be used by local or remote attackers to disclose files (on the local filesystem outside of the expected area), as demonstrated by href=".?../../../../../../../../../../etc/passwd" in an xi:include element.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-5484-1 | librsvg security update |
Ubuntu USN |
USN-6266-1 | librsvg vulnerability |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-02T17:46:56.600Z
Reserved: 2023-07-21T00:00:00.000Z
Link: CVE-2023-38633
No data.
Status : Modified
Published: 2023-07-22T17:15:09.810
Modified: 2024-11-21T08:13:58.380
Link: CVE-2023-38633
OpenCVE Enrichment
No data.
Weaknesses
Debian DSA
Ubuntu USN