ZeroHour

CVE-2023-38633

PoC ×3
CVSS 3.1
5.5 medium
EPSS
2%p83
Published
()
Modified
Description

A directory traversal problem in the URL decoder of librsvg before 2.56.3 could be used by local or remote attackers to disclose files (on the local filesystem outside of the expected area), as demonstrated by href=".?../../../../../../../../../../etc/passwd" in an xi:include element.

Vendors
gnomefedoraprojectdebian
Products
librsvg, fedora, debian linux
Weakness
CWE-22
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.