A directory traversal problem in the URL decoder of librsvg before 2.56.3 could be used by local or remote attackers to disclose files (on the local filesystem outside of the expected area), as demonstrated by href=".?../../../../../../../../../../etc/passwd" in an xi:include element.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2023-07-22T00:00:00

Updated: 2024-08-02T17:46:56.600Z

Reserved: 2023-07-21T00:00:00

Link: CVE-2023-38633

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2023-07-22T17:15:09.810

Modified: 2024-01-24T16:41:49.187

Link: CVE-2023-38633

cve-icon Redhat

Severity : Moderate

Publid Date: 2023-07-22T00:00:00Z

Links: CVE-2023-38633 - Bugzilla