QID 996276
Date Published: 2023-12-14
QID 996276: PHP (Composer) Security Update for phenx/php-svg-lib (GHSA-ff5x-7qg5-vwf2)
When parsing the attributes passed to a use tag inside an svg document, we can cause the system to go to an infinite recursion. Depending on the system configuration and attack pattern this could exhaust the memory available to the executing process and/or to the server itself.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-ff5x-7qg5-vwf2 for updates and patch information.
Vendor References
- GHSA-ff5x-7qg5-vwf2 -
github.com/advisories/GHSA-ff5x-7qg5-vwf2
CVEs related to QID 996276
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-ff5x-7qg5-vwf2 | phenx/php-svg-lib |
|