PT-2023-4918 · Librsvg+8 · Librsvg+8
Zac Sims
·
Publicado
2023-07-11
·
Atualizado
2026-05-19
·
CVE-2023-38633
CVSS v3.1
5.5
Média
| Vetor | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
librsvg versions prior to 2.56.3
Description
The issue is related to a directory traversal problem in the URL decoder of librsvg. This problem can be exploited by local or remote attackers to disclose files on the local filesystem outside of the expected area. The vulnerability can be demonstrated by using a specific
href attribute in an xi:include element, such as href=".?../../../../../../../../../../etc/passwd". This allows attackers to access sensitive information.Recommendations
For versions prior to 2.56.3, update to version 2.56.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the
xi:include element or disabling the URL decoder in librsvg until a patch is available. Avoid using the href attribute in the xi:include element with untrusted input until the issue is resolved.Exploit
Correção
Path traversal
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Alt Linux
Almalinux
Astra Linux
Linuxmint
Red Hat
Red Os
Suse
Ubuntu
Librsvg