PT-2023-31509 · Unknown · Php-Svg-Lib

Cod3Beat

·

Publicado

2023-12-12

·

Atualizado

2024-03-20

·

CVE-2023-50251

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions php-svg-lib versions prior to 0.5.1
Description The issue arises when parsing attributes passed to a use tag inside an SVG document, allowing an attacker to cause the system to go into infinite recursion. This could exhaust the memory available to the executing process and/or the server itself, potentially leading to resource exhaustion if multiple requests are sent to render the payload.
Recommendations For versions prior to 0.5.1, update to version 0.5.1 to resolve the issue. As a temporary workaround, consider restricting the parsing of use tags with href or xlink:href attributes to prevent infinite recursion.

Exploit

Correção

Uncontrolled Recursion

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-50251
DSA-5642-1
GHSA-FF5X-7QG5-VWF2

Produtos afetados

Php-Svg-Lib