Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-38633


A directory traversal problem in the URL decoder of librsvg before 2.56.3 could be used by local or remote attackers to disclose files (on the local filesystem outside of the expected area), as demonstrated by href=".?../../../../../../../../../../etc/passwd" in an xi:include element.


Published

2023-07-22T17:15:09.810

Last Modified

2024-11-21T08:13:58.380

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.5 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-22

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application gnome librsvg < 2.46.6 Yes
Application gnome librsvg < 2.48.11 Yes
Application gnome librsvg < 2.50.8 Yes
Application gnome librsvg < 2.52.10 Yes
Application gnome librsvg < 2.54.6 Yes
Application gnome librsvg < 2.55.3 Yes
Application gnome librsvg < 2.56.3 Yes
Operating System fedoraproject fedora 37 Yes
Operating System fedoraproject fedora 38 Yes
Operating System debian debian_linux 11.0 Yes
Operating System debian debian_linux 12.0 Yes

References