CVE-2023-38633: in librsvg: Arbitrary file read when xinclude href has special characters
A directory traversal problem in the URL decoder of librsvg before 2.56.3 could be used by local or remote attackers to disclose files (on the local filesystem outside of the expected area), as demonstrated by href=".?../../../../../../../../../../etc/passwd" in an xi:include element.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/librsvgto a version that resolves this vulnerability.Fixed in 2.54.7+dfsg-1Fixed in 2.54.7+dfsg-1~deb12u1Fixed in 2.50.3+dfsg-1+deb11u1 - Upgrade
Upgrade
ubuntu/librsvgto a version that resolves this vulnerability.Fixed in 2.56.91Fixed in 2.56.3Fixed in 2.55.3Fixed in 2.54.6Fixed in 2.52.10Fixed in 2.50.8Fixed in 2.48.11Fixed in 2.46.6 - Upgrade
Upgrade
ubuntu/librsvgto a version that resolves this vulnerability.Fixed in 2.48.9-1ubuntu0.20.04.4 - Upgrade
Upgrade
ubuntu/librsvgto a version that resolves this vulnerability.Fixed in 2.52.5+dfsg-3ubuntu0.2 - Upgrade
Upgrade
ubuntu/librsvgto a version that resolves this vulnerability.Fixed in 2.54.5+dfsg-1ubuntu2.1 - Upgrade
Upgrade
debian/librsvgto a version that resolves this vulnerability.Fixed in 2.44.10-2.1+deb10u3Fixed in 2.50.3+dfsg-1+deb11u1Fixed in 2.54.7+dfsg-1~deb12u1Fixed in 2.54.7+dfsg-2 - Upgrade
Upgrade
librsvgto a version that resolves this vulnerability.Fixed in 2.56.3Patch CVE-2023-38633
Event History
Frequently Asked Questions
What is CVE-2023-38633?
CVE-2023-38633 is a vulnerability in librsvg that allows for arbitrary file read when xinclude href has special characters.
How severe is CVE-2023-38633?
CVE-2023-38633 has a severity rating of 5.5/10, which is considered medium.
How can I exploit CVE-2023-38633?
CVE-2023-38633 can be exploited by using a directory traversal technique with specially crafted href in an xi:include element.
What is the affected software for CVE-2023-38633?
The affected software for CVE-2023-38633 includes versions of librsvg before 2.56.3.
How do I fix CVE-2023-38633?
To fix CVE-2023-38633, update to version 2.56.3 or later of librsvg.