USN-6266-1: librsvg vulnerability
Published Aug 1, 2023
·Updated
Zac Sims discovered that librsvg incorrectly handled decoding URLs. A remote attacker could possibly use this issue to read arbitrary files by using an include element.
Affected Software
6 affected componentsFixes available
All of the following
ubuntu/librsvg2-2<2.54.5+dfsg-1ubuntu2.1
2.54.5+dfsg-1ubuntu2.1
Ubuntu Ubuntu=23.04
All of the following
ubuntu/librsvg2-2<2.52.5+dfsg-3ubuntu0.2
2.52.5+dfsg-3ubuntu0.2
Ubuntu Ubuntu=22.04
All of the following
ubuntu/librsvg2-2<2.48.9-1ubuntu0.20.04.4
2.48.9-1ubuntu0.20.04.4
Ubuntu Ubuntu=20.04
Event History
Aug 1, 2023
Advisory Published
via Ubuntu·12:00 AM
Frequently Asked Questions
1
What is the vulnerability ID of this advisory?
The vulnerability ID of this advisory is USN-6266-1.
2
What is the title of this advisory?
The title of this advisory is USN-6266-1: librsvg vulnerability.
3
Who discovered the vulnerability?
Zac Sims discovered the vulnerability.
4
What is the impact of this vulnerability?
The vulnerability allows remote attackers to read arbitrary files using an include element.
5
How can I fix this vulnerability?
To fix this vulnerability, update to version 2.54.5+dfsg-1ubuntu2.1 or later for Ubuntu 23.04, version 2.52.5+dfsg-3ubuntu0.2 or later for Ubuntu 22.04, or version 2.48.9-1ubuntu0.20.04.4 or later for Ubuntu 20.04.