PT-2023-4918 · Librsvg+8 · Librsvg+8

Zac Sims

·

Publicado

2023-07-11

·

Atualizado

2026-05-19

·

CVE-2023-38633

CVSS v3.1

5.5

Média

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions librsvg versions prior to 2.56.3
Description The issue is related to a directory traversal problem in the URL decoder of librsvg. This problem can be exploited by local or remote attackers to disclose files on the local filesystem outside of the expected area. The vulnerability can be demonstrated by using a specific href attribute in an xi:include element, such as href=".?../../../../../../../../../../etc/passwd". This allows attackers to access sensitive information.
Recommendations For versions prior to 2.56.3, update to version 2.56.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the xi:include element or disabling the URL decoder in librsvg until a patch is available. Avoid using the href attribute in the xi:include element with untrusted input until the issue is resolved.

Exploit

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALSA-2023:5081
ALSA-2023_5081
ALT-PU-2023-4760
ALT-PU-2023-4801
ALT-PU-2023-4802
BDU:2023-05427
CVE-2023-38633
DSA-5484-1
ELSA-2023-5081
JLSEC-2026-512
MGASA-2023-0259
OESA-2023-1582
OPENSUSE-SU-2023_3208-1
OPENSUSE-SU-2024:13500-1
RHSA-2023:4809
RHSA-2023:5081
RHSA-2023_5081
ROSA-SA-2023-2276
SUSE-SU-2023:3021-1
SUSE-SU-2023:3208-1
SUSE-SU-2023_3021-1
SUSE-SU-2023_3208-1
USN-6266-1

Produtos afetados

Alt Linux
Almalinux
Astra Linux
Linuxmint
Red Hat
Red Os
Suse
Ubuntu
Librsvg