https://seclists.org/oss-sec/2023/q3/163: CVE-2023-38633 in librsvg: Arbitrary file read when xinclude href has special characters
Published Sep 6, 2023
·Updated
Affected Software
1 affected component
Gnome librsvg
Frequently Asked Questions
1
What is CVE-2023-38633?
CVE-2023-38633 is a vulnerability in Gnome librsvg that allows arbitrary file reading when the xinclude href contains special characters.
2
What are the potential impacts of CVE-2023-38633?
The potential impacts of CVE-2023-38633 include exposure of sensitive files on the system due to improper handling of xinclude hrefs.
3
How do I fix CVE-2023-38633?
To fix CVE-2023-38633, update Gnome librsvg to the latest version where the vulnerability has been addressed.
4
Who reported CVE-2023-38633?
CVE-2023-38633 was reported by Zac Sims.
5
When was CVE-2023-38633 published?
CVE-2023-38633 was published on September 6, 2023.