CVE-2023-38633
Summary
| CVE | CVE-2023-38633 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-07-22 17:15:00 UTC |
| Updated | 2024-01-24 16:41:00 UTC |
| Description | A directory traversal problem in the URL decoder of librsvg before 2.56.3 could be used by local or remote attackers to disclose files (on the local filesystem outside of the expected area), as demonstrated by href=".?../../../../../../../../../../etc/passwd" in an xi:include element. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [SECURITY] Fedora 37 Update: librsvg2-2.54.6-1.fc37 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| CVE-2023-38633: Arbitrary file read when xinclude href has special characters (#996) · Issues · GNOME / librsvg · GitLab |
MISC |
gitlab.gnome.org |
|
| Debian -- Security Information -- DSA-5484-1 librsvg |
DEBIAN |
www.debian.org |
|
| 1213502 – (CVE-2023-38633) VUL-0: CVE-2023-38633: librsvg: directory traversal in URI decoder |
MISC |
bugzilla.suse.com |
|
| oss-security - CVE-2023-38633 in librsvg: Arbitrary file read when xinclude href has
special characters |
MLIST |
www.openwall.com |
|
| When URL parsers disagree (CVE-2023-38633, librsvg) | Hacker News |
MISC |
news.ycombinator.com |
|
| SecLists.Org Security Mailing List Archive |
FULLDISC |
seclists.org |
|
| [SECURITY] Fedora 37 Update: librsvg2-2.54.6-1.fc37 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| CVE-2023-38633 GNOME Librsvg Vulnerability in NetApp Products | NetApp Product Security |
CONFIRM |
security.netapp.com |
|
| [SECURITY] Fedora 38 Update: librsvg2-2.56.3-1.fc38 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| oss-security - Re: CVE-2023-38633 in librsvg: Arbitrary file read
when xinclude href has special characters |
MLIST |
www.openwall.com |
|
| When URL parsers disagree (CVE-2023-38633) - Canva Engineering Blog |
MISC |
www.canva.dev |
|
| 2.56.3 - stable · GNOME / librsvg · GitLab |
CONFIRM |
gitlab.gnome.org |
|
| [SECURITY] Fedora 38 Update: librsvg2-2.56.3-1.fc38 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 199630 Ubuntu Security Notification for librsvg Vulnerability (USN-6266-1)
- 284363 Fedora Security Update for librsvg2 (FEDORA-2023-fc79ee273d)
- 284414 Fedora Security Update for librsvg2 (FEDORA-2023-0873c38acd)
- 296105 Oracle Solaris 11.4 Support Repository Update (SRU) 63.157.1 Missing (CPUOCT2023)
- 503197 Alpine Linux Security Update for librsvg
- 506110 Alpine Linux Security Update for librsvg
- 6000235 Debian Security Update for librsvg (DSA 5484-1)
- 673392 EulerOS Security Update for librsvg2 (EulerOS-SA-2023-3012)
- 673885 EulerOS Security Update for librsvg2 (EulerOS-SA-2023-3035)
- 754252 SUSE Enterprise Linux Security Update for librsvg (SUSE-SU-2023:3208-1)
- 941248 AlmaLinux Security Update for librsvg2 (ALSA-2023:5081)