https://seclists.org/oss-sec/2023/q3/82: CVE-2023-38633 in librsvg: Arbitrary file read when xinclude href has special characters
Published Jul 27, 2023
·Updated
Affected Software
1 affected component
Gnome librsvg>=2.46.6<=2.56.3
Frequently Asked Questions
1
What is the severity of CVE-2023-38633?
CVE-2023-38633 has been classified as a high severity vulnerability due to its potential for arbitrary file read.
2
How do I fix CVE-2023-38633?
To fix CVE-2023-38633, update to the latest version of Gnome librsvg that addresses this vulnerability.
3
What systems are affected by CVE-2023-38633?
CVE-2023-38633 affects Gnome librsvg versions prior to the patch provided for this vulnerability.
4
What are the risks associated with CVE-2023-38633?
The risks of CVE-2023-38633 include unauthorized access to sensitive files through specially crafted xinclude hrefs.
5
Who reported CVE-2023-38633?
CVE-2023-38633 was reported by researcher Zac Sims.