PT-2023-4918 · Librsvg+8 · Librsvg+8
Zac Sims
·
Published
2023-07-11
·
Updated
2026-05-19
·
CVE-2023-38633
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
librsvg versions prior to 2.56.3
Description
The issue is related to a directory traversal problem in the URL decoder of librsvg. This problem can be exploited by local or remote attackers to disclose files on the local filesystem outside of the expected area. The vulnerability can be demonstrated by using a specific
href attribute in an xi:include element, such as href=".?../../../../../../../../../../etc/passwd". This allows attackers to access sensitive information.Recommendations
For versions prior to 2.56.3, update to version 2.56.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the
xi:include element or disabling the URL decoder in librsvg until a patch is available. Avoid using the href attribute in the xi:include element with untrusted input until the issue is resolved.Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Almalinux
Astra Linux
Linuxmint
Red Hat
Red Os
Suse
Ubuntu
Librsvg